CVE-2008-1276
MailEnable Professional/Enterprise <3.13 - Authenticated RCE via IMAP Commands
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1276. PoCs published by haluznik.
AI-analyzed exploit summary This exploit targets a post-authentication buffer overflow in MailEnable Professional <= 3.13 via the IMAP FETCH command. It delivers a bind shell payload on port 4444 after successful authentication.
Description
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote authenticated attackers to execute arbitrary code via long arguments to the (1) FETCH, (2) EXAMINE, and (3) UNSUBSCRIBE commands.
Exploits (1)
This exploit targets a post-authentication buffer overflow in MailEnable Professional <= 3.13 via the IMAP FETCH command. It delivers a bind shell payload on port 4444 after successful authentication.