CVE-2008-6447
QuikSoft EasyMail MailStore ActiveX emmailstore.dll 6.5.0.3 - Buffer Overflow via CreateStore Method
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6447. PoCs published by Francis Provencher, e.wiZz!.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in EasyMail Quicksoft 6.0.2.0 via the CreateStore method in emmailstore.dll, leading to a DoS condition. The PoC uses a long string argument to trigger an access violation.
Description
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a long first argument to the CreateStore method.
Exploits (2)
This exploit targets a buffer overflow vulnerability in EasyMail Quicksoft 6.0.2.0 via the CreateStore method in emmailstore.dll, leading to a DoS condition. The PoC uses a long string argument to trigger an access violation.
This exploit leverages a heap spray technique to trigger a buffer overflow in the EasyMail ActiveX control (emmailstore.dll) via the CreateStore method. The payload includes shellcode designed to execute arbitrary commands, likely resulting in remote code execution.