CVE-2001-1078 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 5.4% (pctl 93)
Patch early
A public exploit exists.
Description
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 5.44% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-06-21 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| extremail | extremail |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | eXtremail 1.x/2.1 - Remote Format String (3) | 2006-10-06 |
| exploit-db | eXtremail 1.5.x (Linux) - Remote Format Strings | 2003-07-02 |
| exploit-db | eXtremail 1.x/2.1 - Remote Format String (1) | 2001-06-21 |
| exploit-db | eXtremail 1.x/2.1 - Remote Format String (2) | 2001-06-21 |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-06/0291.html
- http://www.extremail.com/history.htm
- http://www.extremail.com/news.htm
- http://www.securityfocus.com/bid/2908
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6733
- http://archives.neohapsis.com/archives/bugtraq/2001-06/0291.html
- http://www.extremail.com/history.htm
- http://www.extremail.com/news.htm
- http://www.securityfocus.com/bid/2908
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6733
→ the Explorer · watch your stack · NVD