CVE-2004-1520
IPSwitch IMail 8.13 - Authenticated Stack-Based Buffer Overflow via IMAP DELETE Command
Title source: llmExploitation Summary
EIP tracks 5 public exploits for CVE-2004-1520.
PoCs published by Metasploit, Zatlander, spoonm, including Metasploit module exploits/windows/imap/imail_delete.
AI-analyzed exploit summary This exploit targets a buffer overflow in the 'DELETE' command of the IMail IMAP4D service (CVE-2004-1520). It requires valid credentials and sends a crafted payload to achieve remote code execution on vulnerable Windows systems.
Description
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.
Exploits (5)
This exploit targets a buffer overflow in the 'DELETE' command of the IMail IMAP4D service (CVE-2004-1520). It requires valid credentials and sends a crafted payload to achieve remote code execution on vulnerable Windows systems.
This exploit targets a buffer overflow in MDaemon IMAP 8.0.3's CRAM-MD5 authentication. It sends a maliciously crafted base64-encoded payload to trigger the overflow and achieve remote code execution.
This exploit targets a stack overflow in IPSwitch IMail 8.13 via the DELETE command, using an egghunter and alpha-numeric shellcode to spawn a bind shell on port 4444. It requires valid authentication and leverages ASCII-safe addresses for reliability.
This Metasploit module exploits a buffer overflow in the 'DELETE' command of the IMail IMAP4D service, requiring valid credentials. It targets Windows XP SP0 with a crafted payload to achieve remote code execution.
This Metasploit module exploits a buffer overflow in MDaemon IMAP 8.0.3's CRAM-MD5 authentication. It sends a maliciously crafted base64-encoded payload to trigger a stack-based overflow, leading to remote code execution.