PT-2006-5997 · Hastymail · Hastymail
Published
2006-10-12
·
Updated
2018-10-17
·
CVE-2006-5262
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hastymail versions 1.5 and earlier before 20061008
Description
The issue allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name, potentially crossing privilege boundaries if the IMAP server configuration prevents a user from establishing a direct IMAP session.
Recommendations
For Hastymail versions 1.5 and earlier before 20061008, consider restricting access to the lib/session.php file until a fix is applied, and avoid using CRLF sequences in mailbox names to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hastymail