CVE-2005-2278

MailEnable Professional 1.54 - Authenticated Stack-Based Buffer Overflow via IMAP Status Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-2278. PoCs published by Metasploit, MC, including Metasploit module exploits/windows/imap/mailenable_status.

AI-analyzed exploit summary This is a Metasploit module exploiting a buffer overflow in MailEnable's IMAP server via the STATUS command. It leverages SEH overwrites to achieve remote code execution on vulnerable systems.

Description

Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16485

This is a Metasploit module exploiting a buffer overflow in MailEnable's IMAP server via the STATUS command. It leverages SEH overwrites to achieve remote code execution on vulnerable systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MailEnable IMAP Server 1.54
Auth required
Prerequisites: Valid IMAP credentials · Network access to the IMAP service
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/imap/mailenable_status.rb

This Metasploit module exploits a buffer overflow in MailEnable IMAPD (1.54) via the STATUS command, allowing remote code execution with proper credentials. It uses SEH overwrites and targets multiple Windows versions.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MailEnable IMAPD 1.54
Auth required
Prerequisites: Valid IMAP credentials · Network access to the target IMAP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112127188609993&w=2
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.coresecurity.com/common/showdoc.php?idx=467&idxseccion=10

Scores

EPSS 0.7150
EPSS Percentile 98.8%

Details

Status published
Products (1)
mailenable/mailenable_professional 1.54
Published Jul 18, 2005
Tracked Since Feb 18, 2026