CVE-2008-7078

Rumpus < 6.0 - Buffer Overflow via Long HTTP Verb and Authenticated Buffer Overflow via Long FTP Command Arguments

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-7078. PoCs published by BLUE MOON.

AI-analyzed exploit summary The exploit demonstrates two buffer overflow vulnerabilities in Maxum Rumpus v6.0: one in the HTTP module (DoS via 2908-byte verb) and another in the FTP module (RCE via 1046-byte argument in commands like MKD). The FTP exploit requires authentication but can lead to arbitrary code execution as root.

Description

Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long HTTP verb in the HTTP component; and allow remote authenticated users to execute arbitrary code via a long argument to the (2) MKD, (3) XMKD, (4) RMD, and other unspecified commands in the FTP component.

Exploits (1)

exploitdb WORKING POC VERIFIED
by BLUE MOON · textdoswindows
https://www.exploit-db.com/exploits/7314

The exploit demonstrates two buffer overflow vulnerabilities in Maxum Rumpus v6.0: one in the HTTP module (DoS via 2908-byte verb) and another in the FTP module (RCE via 1046-byte argument in commands like MKD). The FTP exploit requires authentication but can lead to arbitrary code execution as root.

Classification
Working Poc 100%
Attack Type
Rce | Dos
Complexity
Trivial
Reliability
Reliable
Target: Maxum Rumpus v6.0
Auth required
Prerequisites: Network access to target HTTP/FTP ports · Valid credentials for FTP exploitation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Various Sources x_refsource_confirm
http://www.maxum.com/Rumpus/News601.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46988
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7314
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/498786/100/0/threaded
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2008-12/0007.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32892
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32558
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46987
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32560

Scores

EPSS 0.3689
EPSS Percentile 97.2%

Details

CWE
CWE-119
Status published
Products (1)
maxum/rumpus < 6.0
Published Aug 25, 2009
Tracked Since Feb 18, 2026