CVE-2005-2297

Sybase EAServer 4.2.5-5.2 - Authenticated Stack-Based Buffer Overflow via TreeAction.do Javascript Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-2297. PoCs published by Metasploit, Unknown, including Metasploit module exploits/windows/http/sybase_easerver.

AI-analyzed exploit summary This exploit targets a stack buffer overflow in Sybase EAServer 5.2 Web Console via a maliciously crafted GET request to Login.jsp. It leverages SEH overwrites with varying offsets depending on the Java version in use.

Description

Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16766

This exploit targets a stack buffer overflow in Sybase EAServer 5.2 Web Console via a maliciously crafted GET request to Login.jsp. It leverages SEH overwrites with varying offsets depending on the Java version in use.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Racy
Target: Sybase EAServer 5.2
No auth needed
Prerequisites: Network access to the Sybase EAServer Web Console on port 8080 · Target must be running a vulnerable version of Sybase EAServer 5.2 with a compatible Java version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Unknown · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/sybase_easerver.rb

This Metasploit module exploits a stack buffer overflow in Sybase EAServer 5.2 Web Console via a maliciously crafted GET request to Login.jsp. The exploit targets specific JDK versions and leverages SEH overwrites for arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Racy
Target: Sybase EAServer 5.2
No auth needed
Prerequisites: Network access to Sybase EAServer Web Console on port 8080 · Target running a vulnerable JDK version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.sybase.com/detail?id=1036742
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014497
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16108
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112146180532313&w=2

Scores

EPSS 0.7153
EPSS Percentile 98.8%

Details

Status published
Products (4)
sybase/easerver 4.2.5
sybase/easerver 5.0
sybase/easerver 5.1
sybase/easerver 5.2
Published Jul 19, 2005
Tracked Since Feb 18, 2026