{"api_version":"1","generated_at":"2026-07-24T20:47:47+00:00","cve":"CVE-2006-0977","urls":{"html":"https://cve.report/CVE-2006-0977","api":"https://cve.report/api/cve/CVE-2006-0977.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0977","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0977"},"summary":{"title":"CVE-2006-0977","description":"Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to relay all mail through an external SMTP server, which allows remote attackers to relay mail by connecting to the MTS Pro server, then sending a MAIL FROM that specifies a domain that is local to the server.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-03 11:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/16840","name":"http://www.securityfocus.com/bid/16840","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MTS Professional Open EMail Relay Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24985","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24985","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/426181/100/0/threaded","name":"http://www.securityfocus.com/archive/1/426181/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/0786","name":"http://www.vupen.com/english/advisories/2006/0786","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"inode/x-empty","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19067","name":"http://secunia.com/advisories/19067","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Mail Transport System Professional Mail Relay Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0977","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0977","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"977","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"craig_morrison","cpe5":"mts_pro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"977","cve":"CVE-2006-0977","epss":"0.004200000","percentile":"0.620020000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:56:14.549Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-0786","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0786"},{"name":"19067","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19067"},{"name":"16840","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16840"},{"name":"20060225 Mail Transport System Professional--Open Relay Hole","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/426181/100/0/threaded"},{"name":"mts-mail-relay(24985)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24985"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-02-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to relay all mail through an external SMTP server, which allows remote attackers to relay mail by connecting to the MTS Pro server, then sending a MAIL FROM that specifies a domain that is local to the server."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2006-0786","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0786"},{"name":"19067","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19067"},{"name":"16840","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16840"},{"name":"20060225 Mail Transport System Professional--Open Relay Hole","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/426181/100/0/threaded"},{"name":"mts-mail-relay(24985)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24985"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0977","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to relay all mail through an external SMTP server, which allows remote attackers to relay mail by connecting to the MTS Pro server, then sending a MAIL FROM that specifies a domain that is local to the server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-0786","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0786"},{"name":"19067","refsource":"SECUNIA","url":"http://secunia.com/advisories/19067"},{"name":"16840","refsource":"BID","url":"http://www.securityfocus.com/bid/16840"},{"name":"20060225 Mail Transport System Professional--Open Relay Hole","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/426181/100/0/threaded"},{"name":"mts-mail-relay(24985)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24985"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0977","datePublished":"2006-03-03T11:00:00.000Z","dateReserved":"2006-03-03T00:00:00.000Z","dateUpdated":"2024-08-07T16:56:14.549Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-03 11:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:craig_morrison:mts_pro:*:*:*:*:*:*:*:*","matchCriteriaId":"68E91C0D-D555-477C-BA32-2A11D4D1D284"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"977","Ordinal":"1","Title":"CVE-2006-0977","CVE":"CVE-2006-0977","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"977","Ordinal":"1","NoteData":"Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to relay all mail through an external SMTP server, which allows remote attackers to relay mail by connecting to the MTS Pro server, then sending a MAIL FROM that specifies a domain that is local to the server.","Type":"Description","Title":"CVE-2006-0977"},{"CveYear":"2006","CveId":"977","Ordinal":"2","NoteData":"2006-03-03","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"977","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}