10
CVSSv2

CVE-2007-4646

Published: 31/08/2007 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote malicious users to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command.

Vulnerable Product Search on Vulmon Subscribe to Product

hexamail hexamail server 3.0.0.001_lite

Exploits

<?php /* Hexamail Server 300001 (pop3) pre-auth remote overflow poc by rgod retrogodaltervistaorg tested against the Lite one this one crashes the entire server you are in control of eax and ecx, I think arbitrary code execution is possible but a little tricky, see you soon ;) vendor url: wwwhexamailcom/hexamailserver/ ...