vendor:
eXtremail
by:
mu-b
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: eXtremail
Affected Version From: eXtremail 2.1.1
Affected Version To: eXtremail 2.1.1
Patch Exists: NO
Related CWE:
CPE: a:extremail:extremail:2.1.1
Platforms Tested: Linux
2006
eXtremail <=2.1.1 remote root exploit (x86-lnx)
This is a remote root exploit for eXtremail version 2.1.1 and below. It exploits a buffer overflow in the LOGIN command of the admin interface. The exploit allows an attacker to execute arbitrary code with root privileges.
Mitigation:
Upgrade to a patched version of eXtremail.