CVE-2008-7074

i.Scribe 1.88-2.00 - Remote Code Execution via SMTP Server Response Format String

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-7074. PoCs published by Alfons Luja.

AI-analyzed exploit summary This PHP script exploits a format string vulnerability in i.Scribe SMTP client versions 1.88 to 2.00 beta by acting as a fake SMTP server. It sends a malformed string to trigger the vulnerability when the client connects.

Description

Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a server response, which is not properly handled "when displaying the signon message."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alfons Luja · phpdoswindows
https://www.exploit-db.com/exploits/7249

This PHP script exploits a format string vulnerability in i.Scribe SMTP client versions 1.88 to 2.00 beta by acting as a fake SMTP server. It sends a malformed string to trigger the vulnerability when the client connects.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: i.Scribe SMTP client v1.88 to 2.00 beta
No auth needed
Prerequisites: PHP with sockets extension enabled · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Various Sources x_refsource_confirm
http://memecode.com/site/ver.php?id=264
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46970
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32906
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7249
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/50232
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32497

Scores

EPSS 0.0489
EPSS Percentile 90.9%

Details

CWE
CWE-134
Status published
Products (4)
memcode/i.scribe 1.88
memcode/i.scribe 1.89
memcode/i.scribe 1.90
memcode/i.scribe 2.00 alpha1 (10 CPE variants)
Published Aug 25, 2009
Tracked Since Feb 18, 2026