CVE-2007-5094
Ipswitch IMail Server 8.01-8.11 - Remote Code Execution via Malformed Email Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5094. PoCs published by axis.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in IMAIL SMTP Server versions 8.01-8.11 via a crafted SMTP command. It includes shellcode for remote code execution, leveraging a strcpy overflow in the handling of SMTP commands.
Description
Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a set of four different e-mail messages with a long boundary parameter in a certain malformed Content-Type header line, the string "MIME" by itself on a line in the header, and a long Content-Transfer-Encoding header line.
Exploits (1)
This exploit targets a buffer overflow vulnerability in IMAIL SMTP Server versions 8.01-8.11 via a crafted SMTP command. It includes shellcode for remote code execution, leveraging a strcpy overflow in the handling of SMTP commands.