>> Hastymail IMAP and SMTP Variable Handling Command Injection Vulnerability
Title : Hastymail IMAP and SMTP Variable Handling Command Injection Vulnerability VUPEN ID : VUPEN/ADV-2006-3956 CVE ID : CVE-2006-5262 - CVE-2006-5313
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-09
Technical Description
A vulnerability has been identified in Hastymail, which could be exploited by malicious users to execute arbitrary commands. This flaw is due to input validation errors in the "lib/session.php" and "lib/smtp.php" scripts that do not validate certain variables before being passed as arguments to the IMAP and SMTP servers, which could be exploited by authenticated attackers to inject and execute arbitrary commands.