CVE-2009-1776
matt_wright FormMail < 1.92 - Cross-Site Scripting via request and return_link_url Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1776.
AI-analyzed exploit summary This is a detailed technical analysis of multiple vulnerabilities in FormMail 1.92, including XSS, HTTP Response Header Injection, and HTTP Response Splitting. It provides code snippets, attack vectors, and proof-of-concept examples.
Description
Multiple cross-site scripting (XSS) vulnerabilities in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via javascript: URIs in the (1) request and (2) return_link_url parameters.
Exploits (1)
This is a detailed technical analysis of multiple vulnerabilities in FormMail 1.92, including XSS, HTTP Response Header Injection, and HTTP Response Splitting. It provides code snippets, attack vectors, and proof-of-concept examples.