CVE-1999-1051 describes a medium-severity vulnerability in the default configuration of the Matt Wright FormHandler.cgi script. This flaw allows remote, unauthenticated attackers to read arbitrary files on the server by manipulating the 'reply_message_attach' parameter, as the script only restricts access to the /etc/ directory but permits arbitrary directories for attachments. The attack is low complexity, requiring no authentication, and results in a compromise of confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this very old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:matt_wright:formhandler.cgi:1.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:matt_wright:formhandler.cgi:2.0:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:matt_wright:formhandler.cgi:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.