vendor:
Hexamail Server
by:
rgod
N/A
CVSS
N/A
Remote Overflow
Unknown
CWE
Product Name: Hexamail Server
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
2007
Hexamail Server 3.0.0.001 (pop3) pre-auth remote overflow poc
This exploit allows the attacker to crash the entire Hexamail Server by sending a specially crafted request. The attacker has control over the eax and ecx registers, making arbitrary code execution possible, although it is a bit tricky. The exploit has been tested against the Lite version of Hexamail Server.
Mitigation:
Unknown