MTS Professional Open EMail Relay Vulnerability
BID:16840
Info
MTS Professional Open EMail Relay Vulnerability
| Bugtraq ID: | 16840 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2006 12:00AM |
| Updated: | Mar 01 2006 08:26AM |
| Credit: | Craig Morrison is credited with the discovery of this vulnerability. |
| Vulnerable: |
Craig Morrison MTS Professional 0 |
| Not Vulnerable: | |
Discussion
MTS Professional Open EMail Relay Vulnerability
MTS Professional is susceptible to a remote open-email-relay vulnerability. This issue is due to the application's failure to properly verify the source of emails when configured to forward emails.
This issue allows remote attackers to use vulnerable servers to send arbitrary unsolicited bulk email. Attackers may also forge email messages that appear to originate from a trusted mail server.
MTS Professional is susceptible to a remote open-email-relay vulnerability. This issue is due to the application's failure to properly verify the source of emails when configured to forward emails.
This issue allows remote attackers to use vulnerable servers to send arbitrary unsolicited bulk email. Attackers may also forge email messages that appear to originate from a trusted mail server.
Exploit / POC
MTS Professional Open EMail Relay Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
MTS Professional Open EMail Relay Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
Reports indicate the vendor has addressed this issue; this has not been confirmed by Symantec.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
Reports indicate the vendor has addressed this issue; this has not been confirmed by Symantec.
References
MTS Professional Open EMail Relay Vulnerability
References:
References:
- MTS Professional Homepage (Craig Morrison)
- Mail Transport System Professional--Open Relay Hole (Craig Morrison
)