PT-2006-6035 · Hastymail · Hastymail
Publicado
2006-10-17
·
Atualizado
2018-10-17
·
CVE-2006-5313
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hastymail versions 1.5 and earlier before 20061008
Description
The issue allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the
smtp message parameter. This crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct SMTP session.Recommendations
For Hastymail versions 1.5 and earlier before 20061008, avoid using the
smtp message parameter in a way that could allow arbitrary SMTP commands to be sent, until a fix is available. As a temporary workaround, consider restricting access to the SMTP functionality to minimize the risk of exploitation.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hastymail