Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-1999-1051


Vulnerability Score 5.0 5.0
CVE Id CVE-1999-1051
Last Modified 05 Sep 2008 04:18:36
Published 16 Nov 1999 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.

Vulnerable Systems


  • Matt Wright Formhandler.cgi 1.0

  • Matt Wright Formhandler.cgi 2.0

  • Matt Wright Formhandler.cgi 3.0


BUGTRAQ - 19991116 Re: FormHandler.cgi

Last Updated: 27 May 2016 10:35:15