PT-2006-6035 · Hastymail · Hastymail

Publicado

2006-10-17

·

Atualizado

2018-10-17

·

CVE-2006-5313

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Hastymail versions 1.5 and earlier before 20061008
Description The issue allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the smtp message parameter. This crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct SMTP session.
Recommendations For Hastymail versions 1.5 and earlier before 20061008, avoid using the smtp message parameter in a way that could allow arbitrary SMTP commands to be sent, until a fix is available. As a temporary workaround, consider restricting access to the SMTP functionality to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-5313

Produtos afetados

Hastymail