Matthew Wright FormMail CGI (formmail.cgi) Arbitrary Mail Relay

This script is Copyright (C) 1999-2011 Mathieu Perrin


Synopsis :

Arbirtrary commands might be run on the remote host.

Description :

The 'formmail.pl' is installed. This CGI has a well known security flaw
that lets anyone execute arbitrary commands with the privileges of the
HTTP daemon (root or nobody).

Solution :

Remove it from /cgi-bin.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 6.5
(CVSS2#E:H/RL:OF/RC:C)
Public Exploit Available : true

Family: CGI abuses

Nessus Plugin ID: 10076 (formmail_pl.nasl)

Bugtraq ID: 2079

CVE ID: CVE-1999-0172