9.3
CVSSv2

CVE-2008-6922

Published: 10/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote malicious users to execute arbitrary code via a long argument to the (1) CreateUserPath, (2) Logout, (3) DeleteMailByUID, (4) MoveToInbox, (5) MoveToFolder, (6) DeleteMailEx, (7) GetMailDataEx, (8) SetReplySign, (9) SetForwardSign, and (10) SetReadSign methods, which are not properly handled by (a) the POP3 Class ActiveX control (CMailCom.POP3); or a long argument to the (11) AddAttach, (12) SetSubject, (13) SetBcc, (14) SetBody, (15) SetCc, (16) SetFrom, (17) SetTo, and (18) SetFromUID methods, which are not properly handled by the Class ActiveX control (CMailCOM.SMTP), as demonstrated via the indexOfMail parameter to mwmail.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

youngzsoft cmailserver 5.4.6

Exploits

<?php /* CMailServer 546 mvmailasp/CMailCOMdll remote seh overwrite proof of concept exploit by Nine:Situations:Group::bruiser our site: retrogodaltervistaorg/ software site: wwwyoungzsoftnet/cmailserver/ Google dorks: intitle:"Mail Server CMailServer WebMail" ...