PT-2006-6035 · Hastymail · Hastymail

Published

2006-10-17

·

Updated

2018-10-17

·

CVE-2006-5313

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Hastymail versions 1.5 and earlier before 20061008
Description The issue allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the smtp message parameter. This crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct SMTP session.
Recommendations For Hastymail versions 1.5 and earlier before 20061008, avoid using the smtp message parameter in a way that could allow arbitrary SMTP commands to be sent, until a fix is available. As a temporary workaround, consider restricting access to the SMTP functionality to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-5313

Affected Products

Hastymail