Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-103109. PoCs published by Yuri Gushin.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Exim's SPA authentication (CVE-2026-103107) by sending a maliciously crafted base64-encoded payload to overflow a fixed-size buffer in `spa_base64_to_bits()`. It includes shellcode for a reverse shell and supports bruteforce targeting.
Description
Exim 4.43 - 'auth_spa_server()' Remote
Exploits (1)
This exploit targets a buffer overflow vulnerability in Exim's SPA authentication (CVE-2026-103107) by sending a maliciously crafted base64-encoded payload to overflow a fixed-size buffer in `spa_base64_to_bits()`. It includes shellcode for a reverse shell and supports bruteforce targeting.