10
CVSSv2

CVE-2007-1868

Published: 04/04/2007 Updated: 29/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The management service in IBM Tivoli Provisioning Manager for OS Deployment prior to 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote malicious users to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tivoli provisioning manager os deployment 5.1.0.116

Exploits

## # $Id: ibm_tpmfosd_overflowrb 10394 2010-09-20 08:06:27Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' ...