Executive brief
FormMail, a widely used script for processing web-based contact forms, contains a vulnerability that allows remote attackers to execute arbitrary commands on the web server. This could lead to a complete compromise of the server, unauthorized access to sensitive data, or the disruption of website operations. Because this script is often used to handle customer inquiries, an exploit poses a significant risk to both data integrity and organizational reputation.
Technical details
The FormMail CGI script suffers from a command injection vulnerability. Due to insufficient sanitization of user-supplied input, a remote, unauthenticated attacker can craft malicious requests that are passed to the system shell. This allows for the execution of arbitrary commands with the privileges of the web server process. The vulnerability is reachable over the network without any prior authentication or user interaction. Successful exploitation results in a compromise of confidentiality, integrity, and availability.
Affected products
- Matt Wright FormMail unknown
Timeline
- 1995-08-02: disclosed: Initial publication date in NVD database.