Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1498. PoCs published by ryujin.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in NetWin SurgeMail's IMAP service (CVE-2008-1498) to achieve remote code execution. It authenticates, sends a maliciously crafted LIST command with NOP sleds and shellcode, and spawns a reverse shell on port 4444.
Description
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code via a long first argument to the LIST command.
Exploits (1)
This exploit targets a buffer overflow vulnerability in NetWin SurgeMail's IMAP service (CVE-2008-1498) to achieve remote code execution. It authenticates, sends a maliciously crafted LIST command with NOP sleds and shellcode, and spawns a reverse shell on port 4444.