CVE-2009-1029
POP Peeper < 3.4.0.0 - Remote Code Execution via Long Date Header
Title source: llmExploitation Summary
EIP tracks 5 public exploits for CVE-2009-1029.
PoCs published by Metasploit, Jeremy Brown, MC, including Metasploit module exploits/windows/misc/poppeeper_uidl.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in POP Peeper v3.4 via a crafted UIDL string, allowing arbitrary code execution. It uses SEH overwrites and alphanumeric encoding to bypass bad characters.
Description
Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a long Date header, related to Imap.dll.
Exploits (5)
This Metasploit module exploits a stack buffer overflow in POP Peeper v3.4 via a crafted UIDL string, allowing arbitrary code execution. It uses SEH overwrites and alphanumeric encoding to bypass bad characters.
This Metasploit module exploits a stack buffer overflow in POP Peeper v3.4 via a maliciously crafted DATE string, leading to arbitrary code execution. It uses SEH overwrite techniques and alphanumeric mixed encoding to bypass bad characters.
This exploit targets a buffer overflow vulnerability in POP Peeper 3.4.0.0 via the 'Date' field in an email header. It uses SEH overwrite techniques with a universal pop-pop-ret address from Imap.dll and delivers a bind shell payload on port 55555.
This Metasploit module exploits a stack buffer overflow in POP Peeper v3.4 via a crafted UIDL string, allowing arbitrary code execution. It uses SEH overwrites and alphanumeric encoding to bypass bad characters.
This Metasploit module exploits a stack buffer overflow in POP Peeper v3.4 by sending a specially crafted DATE string to a client, allowing arbitrary code execution. It uses SEH overwrites and alphanumeric encoding to bypass bad characters.