6.5
CVSSv2

CVE-2006-5262

Published: 12/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and previous versions prior to 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMAP server configuration prevents a user from establishing a direct IMAP session.

Vulnerable Product Search on Vulmon Subscribe to Product

hastymail hastymail

hastymail hastymail 1.0.1

hastymail hastymail 1.0.2

hastymail hastymail 1.1

hastymail hastymail 1.2

Exploits

source: wwwsecurityfocuscom/bid/20424/info Hastymail is prone to an IMAP / SMTP command-injection vulnerability because it fails to sufficiently sanitize user-supplied input An authenticated malicious user could execute arbitrary IMAP / SMTP commands on the affected mail server processes This may allow the user to send SPAM from the se ...