CVE-2005-2297

Sybase Easerver - Buffer Overflow

Title source: rule

Description

Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16766
metasploit WORKING POC NORMAL
by Unknown · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/sybase_easerver.rb

Scores

EPSS 0.7153
EPSS Percentile 98.7%

Details

Status published
Products (4)
sybase/easerver 4.2.5
sybase/easerver 5.0
sybase/easerver 5.1
sybase/easerver 5.2
Published Jul 19, 2005
Tracked Since Feb 18, 2026