phPay Nu_mail.inc.PHP Open Email Relay Vulnerability
BID:19517
CVE-2006-4210 |Info
phPay Nu_mail.inc.PHP Open Email Relay Vulnerability
| Bugtraq ID: | 19517 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2006 12:00AM |
| Updated: | Aug 15 2006 09:15PM |
| Credit: | beford is credited with the discovery of this vulnerability. |
| Vulnerable: |
phPay phPay 2.02 |
| Not Vulnerable: | |
Discussion
phPay Nu_mail.inc.PHP Open Email Relay Vulnerability
phPay is prone to a remote open-mail-relay vulnerability because the application fails to properly sanitize user-supplied input before using it to generate email messages.
An attacker may leverage the issue to use webservers that are hosting the vulnerable software to send arbitrary unsolicited bulk email. Attackers may also forge email messages that originate from trusted mail servers.
phPay is prone to a remote open-mail-relay vulnerability because the application fails to properly sanitize user-supplied input before using it to generate email messages.
An attacker may leverage the issue to use webservers that are hosting the vulnerable software to send arbitrary unsolicited bulk email. Attackers may also forge email messages that originate from trusted mail servers.
Exploit / POC
phPay Nu_mail.inc.PHP Open Email Relay Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
phPay Nu_mail.inc.PHP Open Email Relay Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].