IBM Domino Web Access upload module inotes6.dll SEH overwrite exploit.
825727e3aded175ca3e3c3e8ad11b552c824070c5e2b4ab525e18606d3e6a02f
This Metasploit module exploits a buffer overflow vulnerability on the UploadControl ActiveX. The vulnerability exists in the handling of the "Attachment_Times" property, due to the insecure usage of the _swscanf. The affected ActiveX is provided by the dwa85W.dll installed with the IBM Lotus iNotes ActiveX installer. This Metasploit module has been tested successfully on IE6-IE9 on Windows XP, Vista and 7, using the dwa85W.dll 85.3.3.0 as installed with Lotus Domino 8.5.3. In order to bypass ASLR the no aslr compatible module dwabho.dll is used. This one is installed with the iNotes ActiveX.
a5379e9a43da683cd4806d1f1e1d548d9998b0760444a32f658bcd9210c0c210
IBM Domino Web Access upload module inotes6.dll SEH overwrite exploit that has the same offset as the dwa7w exploit but the same class id as the original inotes6 exploit.
58ead93457bb90bfbff8414e450da8513143cd665b5b3e055e2f3cc03d82e513
IBM Domino Web Access upload module dwa7w.dll SEH overwrite exploit.
4be19d2899aa0ce523d06bed33750f7f8e3e3c4e6e8c679af4d50895c9aa08c7