QID 50135
Date Published: 2024-01-15
QID 50135: Exim Mail Server Simple Mail Transfer Protocol (SMTP) Smuggling Vulnerability
Exim is a mail transfer agent (MTA) used on Unix-like operating systems. Exim is free software and it aims to be a general and flexible mailer with extensive facilities for checking incoming e-mail.
CVE-2023-51766: Exim allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages that appear to originate from the Exim server, allowing bypass of an SPF protection mechanism.
Affected Versions:
Exim versions up to 4.97
QID Detection Logic (Unauthenticated):
The QID checks for the SMTP banner to check for vulnerable versions of exim.
On successful exploitation, Remote attackers can use a published exploitation technique to inject e-mail messages that appear to originate from the Exim server.
CVEs related to QID 50135
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-51766 |
|