CVE-2007-1868
IBM Tivoli Provisioning Manager for OS Deployment - Remote Code Execution via Malformed Multipart Form Data
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-1868.
PoCs published by Metasploit, including Metasploit module exploits/windows/http/ibm_tpmfosd_overflow.
AI-analyzed exploit summary This is a stack buffer overflow exploit for IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.x, targeting the rembo.exe service. It leverages a crafted Authorization header to trigger the overflow and execute arbitrary code, with specific handling for Windows 2000 SP4 and Windows 2003 targets.
Description
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.
Exploits (2)
This is a stack buffer overflow exploit for IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.x, targeting the rembo.exe service. It leverages a crafted Authorization header to trigger the overflow and execute arbitrary code, with specific handling for Windows 2000 SP4 and Windows 2003 targets.
This is a stack buffer overflow exploit for IBM Tivoli Provisioning Manager for OS Deployment version 5.1.0.x, targeting the rembo.exe component. It leverages a buffer overflow in the Authorization header to achieve remote code execution on Windows 2000 SP4 and Windows 2003 systems.