CVE-2005-1348
MailEnable Enterprise < 1.04 and Professional < 1.54 - Remote Code Execution via HTTP Authorization Header
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2005-1348.
PoCs published by Metasploit, CorryL, including Metasploit module exploits/windows/http/mailenable_auth_header.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in MailEnable's web service via a maliciously crafted Authorization header. It targets versions prior to Enterprise 1.0.5 and Professional 1.55, delivering a payload to achieve remote code execution.
Description
Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorization header.
Exploits (3)
This Metasploit module exploits a buffer overflow in MailEnable's web service via a maliciously crafted Authorization header. It targets versions prior to Enterprise 1.0.5 and Professional 1.55, delivering a payload to achieve remote code execution.
This exploit targets a buffer overflow vulnerability in MailEnable (Enterprise & Professional) via an HTTP request with a maliciously crafted Authorization header. It delivers a shellcode payload to create an administrator user with credentials 'hack:hack'.
This Metasploit module exploits a buffer overflow in MailEnable's web service via a maliciously crafted Authorization header. It targets vulnerable versions of MailEnable Enterprise and Professional editions, delivering a payload to achieve remote code execution.