Exploitation Summary
EIP tracks 3 public exploits for CVE-2004-2086.
PoCs published by Metasploit, [email protected], hdm, including Metasploit module exploits/windows/http/sambar6_search_results.
AI-analyzed exploit summary This exploit targets a buffer overflow in Sambar 6's search results application, leveraging a crafted POST request to execute arbitrary code via a User-Agent header overflow. It includes specific return addresses for Windows 2000 and XP targets.
Description
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.
Exploits (3)
This exploit targets a buffer overflow in Sambar 6's search results application, leveraging a crafted POST request to execute arbitrary code via a User-Agent header overflow. It includes specific return addresses for Windows 2000 and XP targets.
This exploit targets a buffer overflow vulnerability in Sambar web server by sending a maliciously crafted POST request with excessive data. The PoC uses the SMUDGE framework to generate the payload, aiming to trigger a denial of service or potential remote code execution.
This Metasploit module exploits a buffer overflow in Sambar 6's search results application via a maliciously crafted POST request. It leverages a jmp ESP instruction and encoded payload to achieve remote code execution on vulnerable Windows systems.