PT-2015-4939 · Synck Graphica · Synck Graphica Mailform Pro Cgi

Shoji Baba

·

Published

2015-02-27

·

Updated

2015-02-27

·

CVE-2015-0883

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SYNCK GRAPHICA Mailform Pro CGI versions 4.1.4 through 4.1.5
Description The issue allows remote attackers to execute arbitrary code via unspecified vectors when the mailauth module is enabled, due to a problem with sending e-mail messages.
Recommendations For versions 4.1.4 and 4.1.5, consider disabling the mailauth module until a fix is available to prevent exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-0883

Affected Products

Synck Graphica Mailform Pro Cgi