Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-5313

EPSS 1.02% · P77
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-5313

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the smtp_message parameter. NOTE: this crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct SMTP session. NOTE: this is a different type of issue than CVE-2006-5262.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Hastymail IMAP/SMTP远程命令跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Hastymail是一个用PHP编写的快速、安全、兼容RFC、跨平台的IMAP/SMTP客户端应用程序。 Hastymail在处理用户请求时存在输入验证漏洞,远程攻击者可能利用此漏洞在服务器上执行任意命令。 拥有有效Hastymail帐号的用户可以通过在Hastymail变量中嵌入"命令结束"序列直接向IMAP或SMTP服务器发送命令。远程攻击者可以绕过安全限制,尝试攻击IMAP或SMTP服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-5313

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-5313

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-10-17 · 34 CVEs total

CVE-2006-5301phpBB SpamBlockerMODv 'antispam.php'PHP远程文件包含漏洞
CVE-2006-5325phpBB dwingmods Dimitri Seitz Security Suite IP Logger多个PHP远程文件包含漏洞
CVE-2006-5326phpBB Prillian French 'language/lang/lang_contact_faq.php'PHP远程文件包含漏洞
CVE-2006-5309PHPBB Prillian French 'Lang_Prillian_Faq.PHP'远程文件包含漏洞
CVE-2006-5310J-Pierre DEZELUS Les Visiteurs 'menus.inc.php'PHP远程文件包含漏洞
CVE-2006-5311Buzlas 'includes/archive/archive_topic.php'PHP远程文件包含漏洞
CVE-2006-5312phpBB Ajax Shoutbox 'shoutbox.php'PHP远程文件包含漏洞
CVE-2006-5299Gcontact 'index.php'多个跨站脚本攻击漏洞
CVE-2006-5300HP Version Control Agent远程未授权访问及特限提升漏洞
CVE-2006-5324IBM WebSphere Application Server Web Services Notification (WSN)安全组件安全绕过漏洞
CVE-2006-5302Redaction System 多个PHP远程文件包含漏洞
CVE-2006-5303Secure Computing SafeWord RemoteAccess 本地信息泄露漏洞
CVE-2006-5304IncCMS Core 'settings.php' Inc_Dir参数PHP远程文件包含漏洞
CVE-2006-5305Lat2Cyr 'lat2cyr.phpP'PHP远程文件包含漏洞
CVE-2006-5306phpBB的Journals System模块多个PHP远程文件包含漏洞
CVE-2006-5307AFGB GUESTBOOK 多个PHP远程文件包含漏洞
CVE-2006-5308Open Conference Systsems 多个PHP远程文件包含漏洞
CVE-2006-5173Linux 核心EFLAGS位本地拒绝服务漏洞
CVE-2006-5323IBM WebSphere Application Server 未明安全漏洞
CVE-2006-5322phplist 多个SQL注入漏洞

Showing top 20 of 34 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-5313

No comments yet


Leave a comment