AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-5262

MEDIUM · CVSS 6.5 EPSS 2.56%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-10-12 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2006-5262
Severity
MEDIUM
CVSS
6.5
EPSS
2.56%

Original NVD Description

CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMAP server configuration prevents a user from establishing a direct IMAP session.