漏洞描述 SMTP设计之初没有对发送方进行身份验证的机制,导致任意用户可以连接到SMTP服务器进行邮件发送的操作。后来定义了身份认证机制SMTP-AUTH扩展,于其巨大的基数,大量因为未开启验证或者旧版不支持SMTP-AUTH的STMP仍在现网环境运行,导致大量垃圾/诈骗邮件在网上传播
相关漏洞推荐 POC wp-easy-wp-smtp-log-exposure: WordPress Easy WP SMTP - Log Exposure POC smtp-credentials-exposure: SMTP Credentials Exposure - Detection POC wp-wp-mail-smtp-fpd: WordPress WP Mail SMTP - Full Path Disclosure POC CVE-2025-11833: Post SMTP <= 3.6.0 - Email Log Disclosure JBOSS Netty SMTP 未授权 命令注入漏洞 POC CVE-2017-18518: SMTP by BestWebSoft < 1.1.0 - Cross-Site Scripting POC CVE-2019-25141: Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update POC CVE-2020-35234: SMTP WP Plugin Directory Listing POC CVE-2023-6875: WordPress POST SMTP Mailer <= 2.8.7 - Authorization Bypass POC CVE-2020-7247: OpenSMTPD 6.4.0-6.6.1 - Remote Code Execution POC esmtprc-config: eSMTP - Config Discovery POC msmtp-config: Msmtp - Config Exposure POC smtp4dev-interface-exposed: SMTP4Dev Interface - Exposed