CVE-2008-2499
IBM Lotus Sametime < 7.5.1 CF1 and 8.x < 8.0.1 - Remote Code Execution via Crafted URL
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-2499.
PoCs published by Metasploit, Manuel Santamarina Suarez, aushack, including Metasploit module exploits/windows/lotus/domino_sametime_stmux.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in IBM Lotus Domino Sametime STMux.exe via a long POST request to overwrite SEH, leading to remote code execution. It includes multiple targets for different Windows versions and Sametime releases.
Description
Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in IBM Lotus Domino Sametime STMux.exe via a long POST request to overwrite SEH, leading to remote code execution. It includes multiple targets for different Windows versions and Sametime releases.
This exploit targets a buffer overflow vulnerability in IBM Lotus Sametime's StMUX service (CVE-2008-2499) by sending a maliciously crafted POST request to port 1533, overwriting the SE handler and executing a bind shell on port 4444.
This Metasploit module exploits a stack buffer overflow in IBM Lotus Domino Sametime STMux.exe via a long POST request to overwrite SEH. It targets multiple versions of Lotus Sametime on Windows Server 2000/2003.