[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] formail 1.92 april update still insecure



Wouldn't chmod'ing the script to 700 produce the desired (non-spamming)
result?

Batman

> Surfbaud wrote:
> 
>> try this....
>> 
>> http://xx.xxx.xx.xx/cgi-bin/FormMail.pl?recipient=test@xxxxxxxxxxxxxx&subject
>> =Please%20close%20your%20open%20formmail&email=test@xxxxxxxxxxxxxx&=http://xx
>> .xxx.xxx.xxx/cgi-bin/FormMail.pl
> 
> Version 1.9s-p4 passes this test with an error instead of a relay.
> 
> Jeff