CVE-2003-0979
Last modified
CVE-2003-0979 is a vulnerability of currently unknown severity. FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freescripts | Visitorbook | le |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0979?
How severe is CVE-2003-0979?
How do I fix CVE-2003-0979?
Are you affected by CVE-2003-0979?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
