Template / PR Information

Template Validation

I’ve validated this template locally?

  • YES
  • NO

Additional Details (leave it blank if not applicable)

Vulnerability Details:

  • Affects Exim 4.92 through 4.92.2
  • Heap buffer overflow in string_vformat() function triggered by long EHLO command
  • Template sends 1200-character EHLO payload to trigger crash
  • Detection based on vulnerable version + crash response (not version-only)

Test Environment:

Screenshot from 2025-07-01 00-45-30

Screenshot from 2025-07-01 00-46-50

Screenshot from 2025-07-01 00-46-59

Debug Output (Successful Detection):

[CVE-2019-16928:word-1] [tcp] [critical] localhost:8825
[INF] Scan completed in 2.530696ms. 1 matches found.

Response Data Snippet:

220 mail.vulnerable-test.local ESMTP Exim 4.92.2 Tue, 01 Jul 2025 00:24:22 +0000
421 Service not available, closing transmission channel

Shodan Query: "ESMTP Exim 4.92"

Template Features:

  • ✅ Complete POC with actual exploit payload
  • ✅ Exploitation-based detection (not version-only)
  • ✅ Tests multiple SMTP ports (25, 587, 465)
  • ✅ Includes version extraction
  • ✅ KEV listed vulnerability

Additional References:

/claim #12169 /resolve #12169

Claim

Total prize pool $50
Total paid $0
Status Pending
Submitted June 30, 2025
Last updated June 30, 2025

Contributors

RI

Rishi Mondal

@MAVRICK-1

100%

Sponsors

PR

ProjectDiscovery

@projectdiscovery

$50