CVE-2007-4880
IBM Tivoli Storage Manager Client 5.1-5.4 - Remote Code Execution via Crafted HTTP Headers
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2007-4880.
PoCs published by Metasploit, muts, MC, including Metasploit module exploits/windows/http/ibm_tsm_cad_header.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in IBM Tivoli Storage Manager Express CAD Service (5.3.3) via an overly long GET request. It leverages a hardcoded return address in dbghelp.dll to execute arbitrary payloads.
Description
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in IBM Tivoli Storage Manager Express CAD Service (5.3.3) via an overly long GET request. It leverages a hardcoded return address in dbghelp.dll to execute arbitrary payloads.
This exploit targets a buffer overflow vulnerability in IBM Tivoli Storage Manager Express CAD Service 5.3. It sends a crafted HTTP request with a malicious payload to trigger a bind shell on port 4444.
This Metasploit module exploits a stack buffer overflow in IBM Tivoli Storage Manager Express CAD Service (5.3.3) via an overly long GET request, allowing arbitrary code execution. It uses a known return address in dbghelp.dll and includes a payload with specific bad character exclusions.