Vulnerabilities > CVE-2008-0434 - Numeric Errors vulnerability in Gecad Technologies Axigen Mail Server 5.0.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Axigen <= 5.0.2 AXIMilter Remote Format String Exploit. CVE-2008-0434. Remote exploit for linux platform |
file | exploits/linux/remote/4947.c |
id | EDB-ID:4947 |
last seen | 2016-01-31 |
modified | 2008-01-21 |
platform | linux |
port | |
published | 2008-01-21 |
reporter | hempel |
source | https://www.exploit-db.com/download/4947/ |
title | Axigen <= 5.0.2 AXIMilter Remote Format String Exploit |
type | remote |
Nessus
NASL family | Gain a shell remotely |
NASL id | AXIMILTER_FORMAT_STRING.NASL |
description | The version of AXIMilter installed on the remote host fails to sanitize input of format string identifiers. Using a specially- crafted packet, an unauthenticated, remote attacker can crash the service or possibly execute arbitrary code on the remote host subject to the privileges under which the service operates. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 30106 |
published | 2008-01-28 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/30106 |
title | AXIGEN Mail Server AXIMilter CNHO Command Remote Format String |
code |
|
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059788.html
- http://www.securityfocus.com/bid/27363
- http://secunia.com/advisories/28562
- http://securityreason.com/securityalert/3570
- http://www.vupen.com/english/advisories/2008/0237
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39803
- https://www.exploit-db.com/exploits/4947
- http://www.securityfocus.com/archive/1/486722/100/0/threaded