PT-2009-6538 · Zend · Zend Framework

Stefan Esser

·

Published

2009-12-24

·

Updated

2009-12-28

·

CVE-2009-4417

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zend Framework (affected versions not specified)
Description The issue concerns the shutdown function in the Zend Log Writer Mail class, which allows attackers to send arbitrary e-mail messages to any recipient address. This is achieved through vectors related to events not yet mailed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4417

Affected Products

Zend Framework