The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
The STARTTLS implementation
Exploit
CVE-2014-2727
NVD
Refer to CVE-2014-2727 NVD advisory