vendor:
MailEnable
by:
Unknown
7.5
CVSS
HIGH
Heap Buffer Overflow
Unknown
CWE
Product Name: MailEnable
Affected Version From: 1
Affected Version To: 1.18
Patch Exists: NO
Related CWE: Unknown
CPE: mailenable:mailenable
Platforms Tested: Windows
Unknown
Remote Heap Buffer Overflow in MailEnable
The 'Professional' and 'Enterprise' editions of MailEnable are prone to a remote heap buffer overflow. The overflow allows the attacker to control the EAX and ECX registers, allowing arbitrary code execution as SYSTEM. If logging is enabled, the request could contain: GET /{4032 x A} HTTP/1.1 or, without logging: GET /{8501 x A} HTTP/1.1.
Mitigation:
Unknown