Exploitation Summary
EIP tracks 2 public exploits for CVE-2007-0955. PoCs published by mu-b.
AI-analyzed exploit summary This exploit targets a denial-of-service (DoS) vulnerability in Mail Enable Professional/Enterprise by sending malformed NTLM authentication data to the IMAP service. The payload triggers a crash due to improper handling of the authentication process.
Description
The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in an out-of-bounds read.
Exploits (2)
This exploit targets a denial-of-service (DoS) vulnerability in Mail Enable Professional/Enterprise by sending malformed NTLM authentication data to the IMAP service. The payload triggers a crash due to improper handling of the authentication process.
This exploit triggers an out-of-bounds read vulnerability in Mail Enable Professional/Enterprise <=v2.35 via malformed NTLM authentication during IMAP session, leading to a denial-of-service (DoS). The PoC sends crafted base64-encoded payloads to crash the IMAP service.