CVE-2008-3361

IntelliTamper 2.07 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-3361. PoCs published by Wojciech Pawlikowski, Koshi.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in IntelliTamper 2.07 via a maliciously crafted HTTP Location header. It uses a standard stack-based overflow with a NOP sled, a return address override (0x7c941EED from ntdll.dll), and Metasploit-generated Alpha2-encoded shellcode to achieve remote code execution.

Description

Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Server header.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Wojciech Pawlikowski · cremotewindows
https://www.exploit-db.com/exploits/6227

This exploit targets a buffer overflow vulnerability in IntelliTamper 2.07 via a maliciously crafted HTTP Location header. It uses a standard stack-based overflow with a NOP sled, a return address override (0x7c941EED from ntdll.dll), and Metasploit-generated Alpha2-encoded shellcode to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IntelliTamper 2.07
No auth needed
Prerequisites: Network access to the target's HTTP service · IntelliTamper 2.07 running on a vulnerable system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Koshi · perlremotewindows
https://www.exploit-db.com/exploits/6118

This exploit targets a buffer overflow vulnerability in IntelliTamper 2.07 via a maliciously crafted HTTP 'Server' header. It uses a call to ESP in NTDLL.DLL to execute Alpha2-encoded shellcode that spawns calc.exe.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IntelliTamper 2.07
No auth needed
Prerequisites: Network access to the target · Target must be running IntelliTamper 2.07
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44147
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6227
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30356
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6118
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4059

Scores

EPSS 0.0430
EPSS Percentile 89.8%

Details

CWE
CWE-119
Status published
Products (1)
intellitamper/intellitamper 2.0.7
Published Jul 29, 2008
Tracked Since Feb 18, 2026