Mailform Pro CGI 4.3.1.2 and earlier allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
Link | Tags |
---|---|
https://www.synck.com/blogs/news/newsroom/detail_1686638620.html | product |
https://www.synck.com/downloads/cgi-perl/mailformpro/feature_1361268679.html | product |
https://jvn.jp/en/jp/JVN70502982/index.html | third party advisory |