CVE-2016-9492 describes an unrestricted file upload vulnerability in PHP FormMail Generator versions prior to December 17, 2016. The generated form.lib.php file uses an incomplete blacklist of dangerous file extensions, allowing attackers to upload and execute PHP code by exploiting variations not included in the list. This critical vulnerability has a CVSS score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating it can be exploited remotely with low complexity, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion, the high FAUCET Risk Score of 79/100 suggests its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2016-12-17CPE matchmatch criteria | cpe:2.3:a:jqueryform:php_formmail_generator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.