CVE-1999-0512

Mail Server - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0512. PoCs published by Campbell Murray, including Metasploit module auxiliary/scanner/smtp/smtp_relay.

AI-analyzed exploit summary This Metasploit module tests SMTP servers for open relay vulnerabilities by sending various crafted MAIL FROM and RCPT TO commands to detect if the server accepts unauthorized email relaying. It does not exploit the vulnerability but scans for its presence.

Description

A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.

Exploits (1)

metasploit SCANNER
by Campbell Murray · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/smtp/smtp_relay.rb

This Metasploit module tests SMTP servers for open relay vulnerabilities by sending various crafted MAIL FROM and RCPT TO commands to detect if the server accepts unauthorized email relaying. It does not exploit the vulnerability but scans for its presence.

Classification
Scanner 100%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: SMTP servers (various versions)
No auth needed
Prerequisites: network access to the SMTP server
devstral-2 · analyzed Jun 09, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0512

Scores

EPSS 0.7086
EPSS Percentile 98.7%

Details

Status published
Published Jan 01, 1999
Tracked Since Feb 18, 2026