9.3
CVSSv2

CVE-2007-4474

Published: 27/12/2007 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 950
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote malicious users to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm domino web access 6.0.1.1

ibm domino web access 6.0.2

ibm domino web access 6.5.3

ibm domino web access 6.5.4

ibm domino web access 6.0

ibm domino web access 6.0.1

ibm domino web access 6.5.1

ibm domino web access 6.5.2

ibm lotus domino web access 7.0.34.1

ibm domino web access 6.0.3

ibm domino web access 6.0.4

ibm domino web access 6.5.5

ibm domino web access 7.0

ibm domino web access 6.0.5

ibm domino web access 6.5

ibm domino web access 7.0.1

ibm lotus domino web access 7.0.1

Exploits

<!-- written by eb IBM Domino Web Access Upload Module dwa7wdll SEH Overwrite Exploit CVE-2007-4474 Tested on Windows XP SP2(fully patched) English, IE6, dwa7wdll version 70341 Thanks to hdm and the Metasploit crew --> <html> <head> <title>IBM Domino Web Access Upload Module dwa7wdll SEH Overwrite Exploit&lt ...
## # $Id: ibmlotusdomino_dwa_uploadmodulerb 10394 2010-09-20 08:06:27Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require ' ...
<!-- written by eb IBM Domino Web Access Upload Module inotes6dll SEH Overwrite Exploit Bad chars: 0x80+ CVE-2007-4474 Tested on Windows XP SP2(fully patched) English, IE6, inotes6dll version 60400 and version 60480 Thanks to str0ke for pointing me in the right direction and to hdm and the Metasploit crew --> <html> &lt ...
<!-- written by eb IBM Domino Web Access Upload Module Universal BoF Exploit CVE-2007-4474 Tested on Windows XP SP2(fully patched) English, IE6 and IE7 dwa7wdll version 70341 inotes6dll version 60400 and version 60480 inotes6wdll version 60480 Thanks to hdm and the Metasploit crew --> <html> <head> < ...
IBM Domino Web Access upload module inotes6dll SEH overwrite exploit that has the same offset as the dwa7w exploit but the same class id as the original inotes6 exploit ...
IBM Domino Web Access upload module dwa7wdll SEH overwrite exploit ...
IBM Domino Web Access upload module inotes6dll SEH overwrite exploit ...