aluigi.altervista.org
http://aluigi.altervista.org/adv/maildisable-adv.txt CVE-2008-1276
MailEnable Professional/Enterprise 3.13 - 'Fetch' (Authenticated) Remote Buffer Overflow
Record summary
CVE-2008-1276 has a selected CVSS score of 9.0; EIP currently links 1 catalogued exploit.
Description
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote authenticated attackers to execute arbitrary code via long arguments to the (1) FETCH, (2) EXAMINE, and (3) UNSUBSCRIBE commands.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMailEnable Professional/Enterprise 3.13 - 'Fetch' (Authenticated) Remote Buffer OverflowExploitDB exploitby haluznikNot analyzed1 file
References
1029277Third-party advisory
http://secunia.com/advisories/29277 3724Third-party advisory
http://securityreason.com/securityalert/3724 20080307 Multiple vulnerabilities in MailEnable Professional/Enterprise 3.13mailing list
http://www.securityfocus.com/archive/1/489270/100/0/threaded 28145vdb entry
http://www.securityfocus.com/bid/28145 1019565vdb entry
http://www.securitytracker.com/id?1019565 ADV-2008-0799vdb entry
http://www.vupen.com/english/advisories/2008/0799/references mailenable-imapservice-bo(41058)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41058 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-1276 5249exploit
https://www.exploit-db.com/exploits/5249