Vulnerabilities > CVE-2006-5262 - Unspecified vulnerability in Hastymail

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
hastymail
exploit available

Summary

CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMAP server configuration prevents a user from establishing a direct IMAP session.

Exploit-Db

descriptionHastymail 1.x IMAP SMTP Command Injection Vulnerability. CVE-2006-5262. Webapps exploit for php platform
idEDB-ID:28777
last seen2016-02-03
modified2006-10-10
published2006-10-10
reporterVicente Aguilera Diaz
sourcehttps://www.exploit-db.com/download/28777/
titleHastymail 1.x IMAP SMTP Command Injection Vulnerability