CVE-2009-0880

IBM Director < 5.20.3 - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.

Exploits (4)

metasploit WORKING POC EXCELLENT
by Bernhard Mueller, kingcope, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/ibm_director_cim_dllinject.rb
exploitdb WORKING POC
by kingcope · textremotewindows
https://www.exploit-db.com/exploits/23074
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/23203
exploitdb WORKING POC VERIFIED
by Bernhard Mueller · perllocalwindows
https://www.exploit-db.com/exploits/32845

Scores

EPSS 0.6356
EPSS Percentile 98.4%

Classification

CWE
CWE-22
Status draft

Affected Products (15)

ibm/director < 5.20.3
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director
ibm/director

Timeline

Published Mar 12, 2009
Tracked Since Feb 18, 2026