CVE-2016-9493

CVSS V2 Medium 4.3 CVSS V3 Medium 6.1
Description
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.
Overview
  • CVE ID
  • CVE-2016-9493
  • Assigner
  • cret@cert.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2018-07-13T20:29:01
  • Last Modified Date
  • 2019-10-09T23:20:32
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:jqueryform:php_formmail_generator:*:*:*:*:*:*:*:* 1 OR 2016-12-17
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • NONE
  • Base Score
  • 4.3
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 2.9
CVSS Version 3
  • Version
  • 3.0
  • Vector String
  • CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • REQUIRED
  • Scope
  • CHANGED
  • Confidentiality Impact
  • LOW
  • Availability Impact
  • NONE
  • Base Score
  • 6.1
  • Base Severity
  • MEDIUM
  • Exploitability Score
  • 2.8
  • Impact Score
  • 2.7
References
Reference URL Reference Tags
https://www.kb.cert.org/vuls/id/608591 Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/96718 Third Party Advisory VDB Entry
History
Created Old Value New Value Data Type Notes
2022-05-10 17:13:35 Added to TrackCVE
2022-12-03 09:52:56 cert@cert.org cret@cert.org CVE Assigner updated
2022-12-03 09:52:56 2018-07-13T20:29Z 2018-07-13T20:29:01 CVE Published Date updated
2022-12-03 09:52:56 2019-10-09T23:20:32 CVE Modified Date updated
2022-12-03 09:52:56 Modified Vulnerability Status updated