The Web Application Security Consortium is proud to present 'MX Injection: Capturing and Exploiting
Hidden Mail Servers' written by Vicente Aguilera Diaz of Internet Security Auditors. In this article
Vicente discusses how an attacker can inject additional commands into an online web mail application
communicating with an IMAP/SMTP server.
Article Link: http://www.webappsec.org/projects/articles/121106.shtml