CVE-2006-4305
MaxDB < 7.6.00.30 - Remote Code Execution via Long Database Name
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-4305.
PoCs published by Metasploit, MC, including Metasploit module exploits/windows/http/maxdb_webdbm_database.
AI-analyzed exploit summary This exploit targets a stack buffer overflow in MaxDB WebDBM by sending a maliciously crafted HTTP POST request with an overly long database name. It leverages a return address override to execute arbitrary payloads on vulnerable MaxDB versions.
Description
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a WebDBM client.
Exploits (2)
This exploit targets a stack buffer overflow in MaxDB WebDBM by sending a maliciously crafted HTTP POST request with an overly long database name. It leverages a return address override to execute arbitrary payloads on vulnerable MaxDB versions.
This Metasploit module exploits a stack buffer overflow in MaxDB WebDBM by sending a crafted HTTP POST request with an overly long database name, leading to arbitrary code execution with wahttp process privileges.