peter bassill · operator
$ cve CVE-2008-0434 JSON

CVE-2008-0434 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 10.4% (pctl 96)

Patch early

A public exploit exists.

Description

Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS10.35% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2008-01-23
Last modified2026-06-16

Affected (1)

VendorProduct
gecad technologiesaxigen mail server

Public exploits

SourceTitleDate
exploit-dbAxigen 5.0.2 - AXIMilter Remote Format String2008-01-21

References

→ the Explorer  ·  watch your stack  ·  NVD