6.5

CVE-2006-5313

Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the smtp_message parameter.  NOTE: this crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct SMTP session.  NOTE: this is a different type of issue than CVE-2006-5262.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hastymail ≫ Hastymail Version <= 1.5
Hastymail ≫ Hastymail Version 1.0.1
Hastymail ≫ Hastymail Version 1.0.2
Hastymail ≫ Hastymail Version 1.1
Hastymail ≫ Hastymail Version 1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.36% 0.686
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://hastymail.sourceforge.net/security.php
Patch
http://secunia.com/advisories/22308
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/453417/100/0/threaded
http://www.securityfocus.com/bid/20424
Patch
http://www.vupen.com/english/advisories/2006/3956
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/29407