CVE-2009-0880
IBM Director < 5.20.3 - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.
Exploits (4)
metasploit
WORKING POC
EXCELLENT
by Bernhard Mueller, kingcope, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/ibm_director_cim_dllinject.rb
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/23203
exploitdb
WORKING POC
VERIFIED
by Bernhard Mueller · perllocalwindows
https://www.exploit-db.com/exploits/32845
References (8)
Scores
EPSS
0.6356
EPSS Percentile
98.4%
Classification
CWE
CWE-22
Status
draft
Affected Products (15)
ibm/director
< 5.20.3
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
Timeline
Published
Mar 12, 2009
Tracked Since
Feb 18, 2026