CVE-2006-5262: CRLF Injection
CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMAP server configuration prevents a user from establishing a direct IMAP session.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5262?
CVE-2006-5262 has a high severity level due to the potential for remote authenticated users to send arbitrary IMAP commands.
How do I fix CVE-2006-5262?
To fix CVE-2006-5262, upgrade to a version of Hastymail released after October 8, 2006.
What software is affected by CVE-2006-5262?
CVE-2006-5262 affects Hastymail versions 1.5 and earlier.
Can CVE-2006-5262 lead to privilege escalation?
Yes, CVE-2006-5262 can lead to privilege escalation if the IMAP server configuration allows it.
Who can exploit CVE-2006-5262?
CVE-2006-5262 can be exploited by remote authenticated users leveraging a CRLF injection in mailbox names.