PT-2006-6035 · Hastymail · Hastymail
Published
2006-10-17
·
Updated
2018-10-17
·
CVE-2006-5313
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hastymail versions 1.5 and earlier before 20061008
Description
The issue allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the
smtp message parameter. This crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct SMTP session.Recommendations
For Hastymail versions 1.5 and earlier before 20061008, avoid using the
smtp message parameter in a way that could allow arbitrary SMTP commands to be sent, until a fix is available. As a temporary workaround, consider restricting access to the SMTP functionality to minimize the risk of exploitation.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hastymail