CVE-2008-2639
Citect CitectSCADA 6-7 and CitectFacilities 7 - Remote Code Execution via ODBC Server Service
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-2639.
PoCs published by Metasploit, Kevin Finisterre, including Metasploit module exploits/windows/scada/citect_scada_odbc.
AI-analyzed exploit summary This is a Metasploit module exploiting a stack buffer overflow in CitectSCADA's ODBC daemon (CVE-2008-2639). It targets multiple versions of CitectSCADA (v5, v6, v7) by sending a malicious ODBC packet to trigger remote code execution.
Description
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.
Exploits (3)
This is a Metasploit module exploiting a stack buffer overflow in CitectSCADA's ODBC daemon (CVE-2008-2639). It targets multiple versions of CitectSCADA (v5, v6, v7) by sending a malicious ODBC packet to trigger remote code execution.
This is a Metasploit module exploiting a stack overflow in CitectSCADA's ODBC daemon (CVE-2008-2639). It targets multiple versions of CitectSCADA (v5, v6, v7) on various Windows platforms, delivering a reverse shell payload.
This Metasploit module exploits a stack buffer overflow in CitectSCADA's ODBC daemon (CVE-2008-2639) by sending a malicious packet to port 20222, targeting multiple versions of CitectSCADA (v5, v6, v7). It leverages SEH overwrites and a backward jump to execute payloads.