CVE-2008-0871
Now SMS/MMS Gateway < 2007.06.27 - Stack-Based Buffer Overflow via HTTP Authorization Header or SMPP Packet
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-0871.
PoCs published by Metasploit, Heretic2, MC, including Metasploit module exploits/windows/http/nowsms.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in Now SMS/MMS Gateway v2007.06.27 via a crafted GET request with a malicious Authorization header. It achieves remote code execution by leveraging a CALL ESP instruction in SMSHMAC.DLL.
Description
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in Now SMS/MMS Gateway v2007.06.27 via a crafted GET request with a malicious Authorization header. It achieves remote code execution by leveraging a CALL ESP instruction in SMSHMAC.DLL.
This exploit targets a buffer overflow vulnerability in Now SMS/MMS Gateway v5.5, leveraging an egghunter and shellcode to achieve remote code execution. It includes both bind and reverse shell payloads.
This Metasploit module exploits a stack buffer overflow in Now SMS/MMS Gateway v2007.06.27 via a crafted GET request with a malicious Authorization header. It achieves remote code execution by leveraging a CALL ESP instruction in SMSHMAC.DLL.