Smartermail 6919 Exploit |link| -
The attacker sends a crafted calendar invitation or an email with a malicious HTML signature to the target administrator. Because the exploit is a (also known as Persistent XSS), the payload is saved directly on the SmarterMail server’s database.
: SmarterMail versions up to and including Build 6919 and Build 6970. smartermail 6919 exploit
Successful exploitation allows an unauthenticated user to execute arbitrary commands with SYSTEM-level privileges The attacker sends a crafted calendar invitation or
An attacker can send specially crafted serialized .NET objects directly to port 17001 via a TCP socket. smartermail 6919 exploit