7.5
CVSSv2

CVE-2007-4440

Published: 21/08/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and previous versions, allows remote malicious users to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.

Vulnerable Product Search on Vulmon Subscribe to Product

pmail mercury mail transport system

Exploits

## # $Id: mercury_cram_md5rb 9583 2010-06-22 19:11:05Z todb $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class ...
# If there are images in this attachment, they will not be displayed Download the original attachment # Mercury Mail Transport System Remote Stack Based Overflow # Overview # Mercury Mail Transport System: Mercury is a free, standards-based mail server # solution, providing comprehensive, fast server support for all major Internet e- # mail proto ...
/* Mercury/32 451 SMTPD CRAM-MD5 Pre-Auth Remote Stack Overflow(Universal) Public Version 10 wwwph4nt0morg 2007-08-22 Code by: ZhenhanLiu Original POC: wwwmilw0rmcom/exploits/4294 Vuln Analysis: pstgroupblogspotcom/2007/08/tipsmercury-smtpd-auth-cram-md5-prehtml Our Mail-list: listph4nt0morg ...