CVE-2007-3605
EnjoySAP SAP GUI - Stack-Based Buffer Overflow via PrepareToPostHTML Function
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2007-3605.
PoCs published by Metasploit, Mark Litchfield, MC, including Metasploit module exploits/windows/browser/enjoysapgui_preparetoposthtml.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in the EnjoySAP SAP GUI ActiveX Control (kwedit.dll 6400.1.1.41) via the 'PrepareToPostHTML()' method. It delivers a payload through an HTML page with embedded JavaScript to trigger arbitrary code execution.
Description
Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in the EnjoySAP SAP GUI ActiveX Control (kwedit.dll 6400.1.1.41) via the 'PrepareToPostHTML()' method. It delivers a payload through an HTML page with embedded JavaScript to trigger arbitrary code execution.
This exploit demonstrates a stack overflow vulnerability in the EnjoySAP SAP GUI for Windows via the ActiveX control 'kweditcontrol.kwedit.1'. The 'PrepareToPostHTML' function is exploited with a long string to trigger a buffer overflow.
This Metasploit module exploits a stack buffer overflow in the SAP KWEdit ActiveX Control (kwedit.dll 6400.1.1.41) via the 'PrepareToPostHTML()' method. It delivers a crafted HTML page with an overly long string to trigger arbitrary code execution on vulnerable Windows systems.