CVE-2007-2795

Ipswitch IMail <2006.21 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2795. PoCs published by dmc.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Ipswitch IMAP server <=v9.20 (CVE-2007-2795). It crafts a malicious SEARCH command with NOP sleds, SEH overwrite, and shellcode to add a local admin account (USER=r00t PASS=r00tr00t!!).

Description

Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.

Exploits (1)

exploitdb WORKING POC VERIFIED
by dmc · cremotewindows
https://www.exploit-db.com/exploits/9662

This exploit targets a buffer overflow vulnerability in Ipswitch IMAP server <=v9.20 (CVE-2007-2795). It crafts a malicious SEARCH command with NOP sleds, SEH overwrite, and shellcode to add a local admin account (USER=r00t PASS=r00tr00t!!).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ipswitch IMAP server <=v9.20
Auth required
Prerequisites: Network access to the IMAP server · Valid IMAP credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3

Scores

EPSS 0.2445
EPSS Percentile 97.6%

Details

CWE
CWE-119
Status published
Products (2)
ipswitch/imail 2006.1
ipswitch/imail < 2006.2
Published Jan 27, 2009
Tracked Since Feb 18, 2026