CVE-2004-1211
Mercury/32 4.01a - Authenticated Buffer Overflow via IMAP Command Arguments
Title source: llmExploitation Summary
EIP tracks 8 public exploits for CVE-2004-1211.
PoCs published by Metasploit, Jacopo Cervini, MC, including Metasploit module exploits/windows/imap/mercury_rename.
AI-analyzed exploit summary This is a Metasploit module exploiting a stack buffer overflow in Mercury/32 v4.01a IMAP service via the RENAME command. It includes payload delivery and handler setup for remote code execution.
Description
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.
Exploits (8)
This is a Metasploit module exploiting a stack buffer overflow in Mercury/32 v4.01a IMAP service via the RENAME command. It includes payload delivery and handler setup for remote code execution.
This exploit targets a buffer overflow vulnerability in Mercury Mail Transport System (CVE-2004-1211) to achieve remote code execution. It sends a crafted payload to trigger the overflow and execute shellcode that binds a shell on port 4444.
This exploit targets a buffer overflow vulnerability in Mercury Mail 4.01 (Pegasus) IMAP server via the SELECT command. It sends a crafted buffer with a return address and shellcode to achieve remote code execution.
This is a functional remote exploit for Mercury32 IMAP server, leveraging a buffer overflow vulnerability to execute arbitrary shellcode. It supports 14 different IMAP commands to trigger the overflow and includes a bind shell payload.
This exploit targets a buffer overflow vulnerability in Mercury32 IMAP server. It sends a crafted SELECT command with a long string of 'A's followed by a return address and shellcode to achieve remote code execution, binding a shell to port 1981.
This is a functional exploit for CVE-2004-1211 targeting Mercury/32 SMTP Server versions 3.32 to 4.51. It leverages a pre-authentication EIP overwrite vulnerability to execute arbitrary code via a crafted buffer, including a bind shell payload.
This exploit targets a buffer overflow vulnerability in Mercury/32 IMAP4 service by sending a maliciously crafted CHECK command with an oversized payload. The script connects to the target IMAP4 service, authenticates, and triggers the overflow, likely causing a denial of service or potential remote code execution.
This Metasploit module exploits a stack buffer overflow in Mercury/32 v4.01a IMAP service via a malformed RENAME command. It includes payload delivery for remote code execution on vulnerable Windows systems.