4.6
CVSSv2

CVE-2005-2297

Published: 19/07/2005 Updated: 18/10/2016
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 up to and including 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sybase easerver 5.2

sybase easerver 4.2.5

sybase easerver 5.0

sybase easerver 5.1

Exploits

## # $Id: sybase_easerverrb 9583 2010-06-22 19:11:05Z todb $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class M ...