CVE-2007-5067
iMatix Xitami Web Server 2.5c2 - Remote Code Execution via Long If-Modified-Since Header
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2007-5067.
PoCs published by Metasploit, h07, including Metasploit module exploits/windows/http/xitami_if_mod_since.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in Xitami Web Server via an overly long If-Modified-Since header. It uses an egghunter technique to bypass size constraints and execute arbitrary payloads.
Description
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long If-Modified-Since header to (1) xigui32.exe or (2) xitami.exe.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in Xitami Web Server via an overly long If-Modified-Since header. It uses an egghunter technique to bypass size constraints and execute arbitrary payloads.
This exploit targets a buffer overflow vulnerability in Xitami Web Server 2.5 via the 'If-Modified-Since' header. It uses a JMP ESP instruction from shell32.dll to redirect execution to a calc.exe shellcode payload.
This Metasploit module exploits a stack buffer overflow in Xitami Web Server via a maliciously crafted If-Modified-Since header. It uses an egghunter technique to bypass size constraints and achieve remote code execution.