A vulnerability has been identified in B21Soft BASP21, which could be exploited to bypass security restrictions. This issue is due to input validation errors in the "Bsmtp.dll" library that does not validate certain email fields, which could be exploited by attackers to inject arbitrary email headers and send spam messages via a vulnerable application.
Credits
Vulnerability reported by Tomoki Sanaki
ChangeLog
2007-03-27 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.