[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] formail 1.92 april update still insecure



Surfbaud wrote:

> try this....
> 
> http://xx.xxx.xx.xx/cgi-bin/FormMail.pl?recipient=test@xxxxxxxxxxxxxx&subject=Please%20close%20your%20open%20formmail&email=test@xxxxxxxxxxxxxx&=http://xx.xxx.xxx.xxx/cgi-bin/FormMail.pl

Version 1.9s-p4 passes this test with an error instead of a relay.

Jeff
-- 
Jeff Lasman <jblists@xxxxxxxxxxxxx>
Linux and Cobalt/Sun/RaQ Consulting
nobaloney.net
P. O. Box 52672, Riverside, CA  92517
voice: (909) 778-9980  *  fax: (702) 548-9484