Lucene search

K

Hastymail Security Vulnerabilities

cve
cve

CVE-2004-2704

Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the download link, which facilitates...

5.8AI Score

0.044EPSS

2007-10-06 09:00 PM
24
cve
cve

CVE-2006-5313

Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the smtp_message parameter. NOTE: this crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct.....

6.7AI Score

0.03EPSS

2006-10-17 05:07 PM
18
cve
cve

CVE-2006-5262

CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMAP server configuration prevents a user from.....

6.8AI Score

0.03EPSS

2006-10-12 10:07 PM
16