Exploitation Summary
EIP tracks 4 public exploits for CVE-2007-4440.
PoCs published by Metasploit, ZhenHan.Liu, eliteboy, including Metasploit module exploits/windows/smtp/mercury_cram_md5.
AI-analyzed exploit summary This exploit targets a stack buffer overflow in Mercury Mail Transport System 4.51 via a maliciously crafted AUTH CRAM-MD5 command. It sends a base64-encoded payload to trigger arbitrary code execution.
Description
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.
Exploits (4)
This exploit targets a stack buffer overflow in Mercury Mail Transport System 4.51 via a maliciously crafted AUTH CRAM-MD5 command. It sends a base64-encoded payload to trigger arbitrary code execution.
This exploit targets a stack overflow vulnerability in Mercury/32 4.51 SMTPD during CRAM-MD5 authentication. It sends a maliciously crafted base64-encoded payload to trigger a buffer overflow, leading to remote code execution and binding a command shell on port 1154.
This exploit targets a stack-based buffer overflow in Mercury Mail Transport System's SMTP server by sending an excessively long AUTH CRAM-MD5 string. The PoC demonstrates the vulnerability but does not include a payload for remote code execution.
This Metasploit module exploits a stack buffer overflow in Mercury Mail Transport System 4.51 via a crafted AUTH CRAM-MD5 command. It sends a malicious payload to achieve remote code execution on the target system.