Record summary

CVE-2011-1213 has a selected CVSS score of 9.3; EIP currently links 3 catalogued exploits.

Description

Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBLotus Notes 8.0.x < 8.5.2 FP2 - Autonomy Keyview ('.lzh' Attachment) (Metasploit)ExploitDB exploitby MetasploitNot analyzed1 file
ExploitDB

PoC details
MetasploitLotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)Metasploit exploitby alino <26alino@gmail.com> +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details
MetasploitLotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)Metasploit exploitby alino <26alino@gmail.com> +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

8