CVE-2010-5289
IncrediMail 2.0 - Buffer Overflow in Authenticate Method via Long String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-5289. PoCs published by d3b4g.
AI-analyzed exploit summary This is a proof-of-concept exploit for a buffer overflow vulnerability in IncrediMail 2.0's ActiveX control (ImSpoolU.dll). The exploit triggers an ACCESS_VIOLATION by passing an overly long string to the 'Authenticate' method, demonstrating potential for arbitrary code execution.
Description
Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in the first argument.
Exploits (1)
This is a proof-of-concept exploit for a buffer overflow vulnerability in IncrediMail 2.0's ActiveX control (ImSpoolU.dll). The exploit triggers an ACCESS_VIOLATION by passing an overly long string to the 'Authenticate' method, demonstrating potential for arbitrary code execution.