CVE-2011-4554 Information

Description

One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) \ (double quote) and newline characters in an org name or (2) \ (double quote) characters in an e-mail address related to a \2nd Order SMTP Injection\ issue.

Reference

http://dmcdonald.net/?page_id=43 https://groups.google.com/group/oneclickorgs-devspace/msg/26c40a4cc9e127d2?hl=en&dmode=source&output=gplain

Share on: