vendor:
MailMax
by:
localh0t
N/A
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: MailMax
Affected Version From: MailMax v4.0
Affected Version To: MailMax v4.6
Patch Exists: NO
Related CWE: CVE-2012-xxxxx
CPE: a:mailmax:mailmax:4.6
Platforms Tested: Windows XP SP3 Spanish
2012
MailMax <=v4.6 POP3 "USER" Remote Buffer Overflow Exploit (No Login Needed)
A hard one this, the shellcode MUST be lowercase. Plus there are many opcode's that break the payload and opcodes that gets changed, like "xc3" gets converted to "xe3", and "xd3" gets converted to "xf3"
Mitigation:
Update to a newer version of MailMax that is not vulnerable.