CVE-2002-2109

Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.

Scoring

CVSS base score
0.03
EPSS probability
0.52%
Published
2005-08-05
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs