Mercury Mail ph Server Remote Overflow

This script is Copyright (C) 2006-2016 Tenable Network Security, Inc.

Synopsis :

The remote ph service is affected by a buffer overflow vulnerability.

Description :

The remote host is running the Mercury Mail Transport System, a free
suite of server products for Windows and Netware associated with
Pegasus Mail.

The remote installation of Mercury includes a ph server that is
vulnerable to buffer overflow attacks. By leveraging this issue, an
unauthenticated, remote attacker is able to crash the remote service
and possibly execute arbitrary code remotely.

See also :

Solution :

Install the Jan 2006 Mercury/32 Security patches for MercuryW and

Risk factor :

High / CVSS Base Score : 7.5
CVSS Temporal Score : 6.2
Public Exploit Available : true

Family: Gain a shell remotely

Nessus Plugin ID: 20812 ()

Bugtraq ID: 16396

CVE ID: CVE-2005-4411

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now