PT-2015-4939 · Synck Graphica · Synck Graphica Mailform Pro Cgi
Shoji Baba
·
Published
2015-02-27
·
Updated
2015-02-27
·
CVE-2015-0883
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SYNCK GRAPHICA Mailform Pro CGI versions 4.1.4 through 4.1.5
Description
The issue allows remote attackers to execute arbitrary code via unspecified vectors when the mailauth module is enabled, due to a problem with sending e-mail messages.
Recommendations
For versions 4.1.4 and 4.1.5, consider disabling the mailauth module until a fix is available to prevent exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Synck Graphica Mailform Pro Cgi