Exploitation Summary
EIP tracks 2 public exploits for CVE-2013-5447.
PoCs published by Metasploit, including Metasploit module exploits/windows/fileformat/ibm_forms_viewer_fontname.
AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in IBM Forms Viewer via a malformed XFDL file with an overly long fontname value. It achieves remote code execution by leveraging a Unicode-compatible payload and SEH overwrite.
Description
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XFDL form with a long fontname value.
Exploits (2)
This Metasploit module exploits a stack-based buffer overflow in IBM Forms Viewer via a malformed XFDL file with an overly long fontname value. It achieves remote code execution by leveraging a Unicode-compatible payload and SEH overwrite.
This Metasploit module exploits a stack-based buffer overflow in IBM Forms Viewer via a malformed XFDL file with an overly long fontname value. It achieves remote code execution by leveraging a Unicode-compatible payload and SEH overwrite.