CVE-2009-4417 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4417): The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages to any recipient address via vectors related to "events not yet mailed."
There is a new 1.9.7 version that fixes several security related bugs, but I didn't see a reference to this issue. http://framework.zend.com/changelog/1.9.7
From the advisory it seems that piwik shipped their own ZF1 parts which in combination with piwik's user input handling caused the vulnerability. There's also mentions of generic ZF exploits, but no specifics here. Since the report is over 3 years old, I suggest we close this.
Thanks Ben and Matti.