E-mail injection

Email Injections

Inject Cc and Bcc after sender argument

Inject argument

Inject Subject argument

Change the body of the message

Two-line feed to change the body of the message

Inject in the e-mail name

  • +, - and {} are rarely used for tagging and ignored by many e-mail servers

    Example:

  • Comments between parentheses () at the beginning or the end are also ignored

    Example:

IPs

IPs as domain named between square brackets:

  • john.doe@[127.0.0.1]

  • john.doe@[IPv6:2001:db8::1]

Other vulnerabilities

XSS

Template Injections

SQL injection

SSRF

Parameter pollution

(Email) header injection

Wildcard abuse

Last updated