Record summary

CVE-2004-2677 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBQwik SMTP 0.3 - Format StringExploitDB exploitby Carlos BarrosNot analyzed1 file
ExploitDB

PoC details

References

9