CVE-2006-5262

Hastymail < 1.5 - Authenticated IMAP Command Injection via CRLF in Mailbox Name

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5262. PoCs published by Vicente Aguilera Diaz.

AI-analyzed exploit summary This exploit demonstrates IMAP/SMTP command injection in Hastymail by injecting arbitrary commands via unsanitized input in the mailbox parameter and SMTP headers. It allows authenticated users to execute commands like CREATE on the IMAP server or send spoofed emails via SMTP.

Description

CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMAP server configuration prevents a user from establishing a direct IMAP session.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Vicente Aguilera Diaz · textwebappsphp
https://www.exploit-db.com/exploits/28777

This exploit demonstrates IMAP/SMTP command injection in Hastymail by injecting arbitrary commands via unsanitized input in the mailbox parameter and SMTP headers. It allows authenticated users to execute commands like CREATE on the IMAP server or send spoofed emails via SMTP.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Hastymail 1.5 and prior
Auth required
Prerequisites: Authenticated access to Hastymail · IMAP/SMTP server reachable from the application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29407
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/453417/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3956
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22308
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20424

Scores

EPSS 0.0254
EPSS Percentile 82.9%

Details

Status published
Products (5)
hastymail/hastymail 1.0.1
hastymail/hastymail 1.0.2
hastymail/hastymail 1.1
hastymail/hastymail 1.2
hastymail/hastymail < 1.5
Published Oct 12, 2006
Tracked Since Feb 18, 2026