7.5
CVSSv2

CVE-2007-3614

Published: 06/07/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 up to and including 7.5, allow remote malicious users to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."

Vulnerable Product Search on Vulmon Subscribe to Product

sap sap db 7.4.03.30

sap sap db 7.4.3

sap sap db 7.4

sap sap db 7.4.03.29

sap sap db 7.4.3.7_beta

sap sap db 7.5

sap sap db 7.3.00

sap sap db 7.3.29

Exploits

source: wwwsecurityfocuscom/bid/24773/info SAP DB Web Server is prone to multiple buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized buffer Successfully exploiting these issues will allow an attacker to execute arbitrary code with SYSTEM-level priv ...
/* Dreatica-FXP crew * * ---------------------------------------- * Target : SAP DB 74 WebTools * Site : wwwsapdborg * Found by : NGSSoftware Insight Security Research * ---------------------------------------- * Exploit : SAP DB 74 WebTools Remote SEH overwrite exploit * Exploit date : 07072007 * Ex ...
## # $Id: sapdb_webtoolsrb 9842 2010-07-16 02:33:25Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class M ...