Vulnerabilities > CVE-2004-1520 - Unspecified vulnerability in Ipswitch Imail 8.13
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Mdaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow. CVE-2004-1520. Remote exploit for windows platform id EDB-ID:16477 last seen 2016-02-01 modified 2010-06-22 published 2010-06-22 reporter metasploit source https://www.exploit-db.com/download/16477/ title Mdaemon 8.0.3 - IMAPD CRAM-MD5 Authentication Overflow description IPSwitch IMail 8.13 (DELETE) Remote Stack Overflow Exploit. CVE-2004-1520. Remote exploit for windows platform id EDB-ID:627 last seen 2016-01-31 modified 2004-11-12 published 2004-11-12 reporter Zatlander source https://www.exploit-db.com/download/627/ title IPSwitch IMail 8.13 DELETE Remote Stack Overflow Exploit description MDaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow Exploit. CVE-2004-1520. Remote exploit for windows platform id EDB-ID:1151 last seen 2016-01-31 modified 2005-08-12 published 2005-08-12 reporter N/A source https://www.exploit-db.com/download/1151/ title MDaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow Exploit description IMail IMAP4D Delete Overflow. CVE-2004-1520. Remote exploit for windows platform id EDB-ID:16479 last seen 2016-02-01 modified 2010-09-20 published 2010-09-20 reporter metasploit source https://www.exploit-db.com/download/16479/ title IMail IMAP4D Delete Overflow
Metasploit
description This module exploits a buffer overflow in the 'DELETE' command of the IMail IMAP4D service. This vulnerability can only be exploited with a valid username and password. This flaw was patched in version 8.14. id MSF:EXPLOIT/WINDOWS/IMAP/IMAIL_DELETE last seen 2019-12-22 modified 2017-09-14 published 2005-12-05 references https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1520 reporter Rapid7 source https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/imap/imail_delete.rb title IMail IMAP4D Delete Overflow description This module exploits a buffer overflow in the CRAM-MD5 authentication of the MDaemon IMAP service. This vulnerability was discovered by Muts. id MSF:EXPLOIT/WINDOWS/IMAP/MDAEMON_CRAM_MD5 last seen 2020-06-01 modified 2017-07-24 published 2005-12-05 references https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1520 reporter Rapid7 source https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/imap/mdaemon_cram_md5.rb title Mdaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow
Nessus
NASL family | Windows |
NASL id | IPSWITCH_IMAIL_BO2.NASL |
description | The remote host is running a version of Ipswitch IMail that is older than version 8.14.0. The remote version of this software is vulnerable to a buffer overflow when it processes the argument of the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15771 |
published | 2004-11-19 |
reporter | This script is Copyright (C) 2004-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/15771 |
title | Ipswitch IMail IMAP Service DELETE Command Remote Overflow |
code |
|
Packetstorm
data source https://packetstormsecurity.com/files/download/83023/imail_delete.rb.txt id PACKETSTORM:83023 last seen 2016-12-05 published 2009-11-26 reporter spoonm source https://packetstormsecurity.com/files/83023/IMail-IMAP4D-Delete-Overflow.html title IMail IMAP4D Delete Overflow data source https://packetstormsecurity.com/files/download/82989/mdaemon_cram_md5.rb.txt id PACKETSTORM:82989 last seen 2016-12-05 published 2009-11-26 reporter anonymous source https://packetstormsecurity.com/files/82989/Mdaemon-8.0.3-IMAPD-CRAM-MD5-Authentication-Overflow.html title Mdaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow
Saint
bid | 11675 |
description | IMail IMAP DELETE command buffer overflow |
id | mail_imap_imail |
osvdb | 11838 |
title | imail_imap_delete |
type | remote |
References
- http://marc.info/?l=bugtraq&m=110037283803560&w=2
- http://marc.info/?l=bugtraq&m=110037283803560&w=2
- http://secunia.com/advisories/13200
- http://secunia.com/advisories/13200
- http://www.securityfocus.com/bid/11675
- http://www.securityfocus.com/bid/11675
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18058
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18058