vendor:
Postcast Server Pro
by:
rgod
7.5
CVSS
HIGH
Remote Buffer Overflow
CWE
Product Name: Postcast Server Pro
Affected Version From: 3.0.61
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 with Internet Explorer 6
Postcast Server Pro 3.0.61 / Quiksoft EasyMail SMTP Object Remote Buffer Overflow Exploit
The exploit allows an attacker to pass more than 539 characters to the SubmitToExpress method in Postcast Server Pro 3.0.61 / Quiksoft EasyMail SMTP Object (emsmtp.dll 6.0.1). This results in a buffer overflow vulnerability, leading to a remote code execution.
Mitigation:
Apply the latest patch or update from the vendor.