Vulnerabilities > CVE-2003-1192 - Buffer Overrun vulnerability in IA WebMail Server Long GET Request

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
truenorth-software
critical
exploit available
metasploit

Summary

Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.

Vulnerable Configurations

Part Description Count
Application
Truenorth_Software
2

Exploit-Db

  • descriptionIA WebMail 3.x Buffer Overflow. CVE-2003-1192. Remote exploit for windows platform
    idEDB-ID:16767
    last seen2016-02-02
    modified2010-05-09
    published2010-05-09
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16767/
    titleIA WebMail 3.x - Buffer Overflow
  • descriptionIA WebMail Server 3.0/3.1 Long GET Request Buffer Overrun Vulnerability. CVE-2003-1192. Remote exploit for windows platform
    idEDB-ID:23334
    last seen2016-02-02
    modified2003-11-03
    published2003-11-03
    reporterPeter Winter-Smith
    sourcehttps://www.exploit-db.com/download/23334/
    titleIA WebMail Server 3.0/3.1 Long GET Request Buffer Overrun Vulnerability
  • descriptionIA WebMail 3.x (iaregdll.dll version 1.0.0.5) Remote Exploit. CVE-2003-1192. Remote exploit for windows platform
    idEDB-ID:124
    last seen2016-01-31
    modified2003-11-19
    published2003-11-19
    reporterPeter Winter-Smith
    sourcehttps://www.exploit-db.com/download/124/
    titleIA WebMail 3.x - iaregdll.dll 1.0.0.5 Remote Exploit

Metasploit

descriptionThis exploits a stack buffer overflow in the IA WebMail server. This exploit has not been tested against a live system at this time.
idMSF:EXPLOIT/WINDOWS/HTTP/IA_WEBMAIL
last seen2020-05-23
modified2017-07-24
published2006-10-03
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/http/ia_webmail.rb
titleIA WebMail 3.x Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/82938/ia_webmail.rb.txt
idPACKETSTORM:82938
last seen2016-12-05
published2009-11-26
reporterH D Moore
sourcehttps://packetstormsecurity.com/files/82938/IA-WebMail-3.x-Buffer-Overflow.html
titleIA WebMail 3.x Buffer Overflow