CVE-2007-5243 describes multiple stack-based buffer overflow vulnerabilities in Borland InterBase versions LI 8.0.0.53 through 8.1.0.253 and WI 5.1.1.680 through 8.1.0.257. The vulnerabilities exist in several functions, including SVC_attach, INET_connect, isc_create_database, jrd8_create_database, isc_attach_database, PWD_db_aliased, jrd8_attach_database, and expand_filename2. Remote attackers can exploit these flaws by sending specially crafted, overly long requests to TCP port 3050, leading to stack corruption and potential arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a single Metasploit exploit module targeting a stack buffer overflow vulnerability in the Firebird (Borland InterBase) database service (CVE-2007-5243). The exploit works by sending a specially crafted SVC_attach() request to the service over TCP port 3050, causing a buffer overflow and allowing arbitrary code execution. The module supports brute-forcing targets and includes hardcoded return addresses for specific vulnerable versions of Firebird on Windows. The payload is customizable via the Metasploit framework, enabling the attacker to execute arbitrary shellcode on the compromised system. The code is written in Ruby and follows the standard Metasploit module structure, making it easy to use within the framework. The only fingerprintable endpoint is the default Firebird service port (3050/tcp).
This repository contains a single Metasploit exploit module targeting a stack buffer overflow vulnerability in Borland InterBase (CVE-2007-5243) on Linux. The exploit works by sending a specially crafted database creation request to the InterBase service running on TCP port 3050. The module allows the attacker to execute arbitrary code (Metasploit payloads) on the target system with the privileges of the InterBase service. The exploit is operational and leverages the Metasploit framework's payload system, making it flexible for various post-exploitation actions. The code is written in Ruby and is structured as a standard Metasploit module, with all logic contained in a single file. No hardcoded IP addresses or URLs are present; the only fingerprintable endpoint is the default InterBase TCP port (3050).
This repository contains a single Metasploit module (Ruby file) that exploits a stack buffer overflow vulnerability in Borland InterBase's isc_attach_database() function (CVE-2007-5243). The exploit targets multiple versions of Borland InterBase running on Windows, specifically those listening on TCP port 3050. The module constructs a specially crafted attach request to trigger the overflow and execute arbitrary code (Metasploit payload) on the target system. The payload is customizable and can be any standard Metasploit payload (e.g., reverse shell, meterpreter). The exploit is operational and provides remote code execution with the privileges of the InterBase service. The file structure is typical for a Metasploit exploit module, and the code leverages Metasploit's TCP and brute force targeting mixins. No hardcoded IP addresses or URLs are present; the only fingerprintable endpoint is the TCP port 3050 used by InterBase.
This repository contains a single Metasploit module (modules/exploits/linux/misc/ib_inet_connect.rb) that exploits a stack buffer overflow vulnerability in Borland InterBase (CVE-2007-5243) on Linux. The exploit works by sending a specially crafted service attach request to the InterBase service, which listens on TCP port 3050. The module allows the attacker to execute arbitrary code (Metasploit payload) on the target system with the privileges of the InterBase service. The exploit targets specific versions of InterBase (LI-V8.0.0.53, LI-V8.0.0.54, LI-V8.1.0.253) and is operational, requiring the attacker to supply a compatible payload. The code is written in Ruby and is structured as a standard Metasploit exploit module, making use of the framework's payload and handler mechanisms. No hardcoded IP addresses, URLs, or file paths are present; the only fingerprintable endpoint is the default TCP port 3050 used by InterBase.
This repository contains a single Metasploit module (ib_isc_create_database.rb) that exploits a stack buffer overflow vulnerability (CVE-2007-5243) in Borland InterBase for Windows. The exploit targets the isc_create_database() function by sending a specially crafted request to the InterBase service, which listens on TCP port 3050. The module supports multiple specific InterBase versions, each with tailored buffer lengths and return addresses. The exploit allows for arbitrary code execution with the privileges of the InterBase service, and the payload is customizable via Metasploit's payload system (e.g., reverse shell, meterpreter). The module is operational and can be used to gain remote access to vulnerable systems. The repository structure is typical for Metasploit, with the exploit implemented as a Ruby class inheriting from Msf::Exploit::Remote, and all relevant configuration and targeting information defined within the module.
This repository contains a single Metasploit module (ib_pwd_db_aliased.rb) that exploits a stack buffer overflow vulnerability (CVE-2007-5243) in Borland InterBase (versions LI-V8.0.0.53, LI-V8.0.0.54, and LI-V8.1.0.253) on Linux. The exploit works by sending a specially crafted attach request to the InterBase service running on TCP port 3050, causing a buffer overflow and allowing execution of arbitrary code with elevated privileges. The module allows the attacker to supply a custom payload (up to 512 bytes, avoiding certain bad characters), which can be used to gain remote access or execute commands on the target system. The code is written in Ruby and is structured as a standard Metasploit exploit module, making use of the Metasploit framework's TCP and payload handling capabilities. No hardcoded IP addresses or URLs are present; the only fingerprintable endpoint is the default InterBase TCP port (3050).
This repository contains a single Metasploit module (ib_svc_attach.rb) that exploits a stack buffer overflow vulnerability (CVE-2007-5243) in Borland InterBase for Windows. The exploit targets the SVC_attach() function by sending a specially crafted service attach request to the InterBase service, which listens by default on TCP port 3050. The module supports multiple specific InterBase versions, each with tailored buffer lengths and return addresses. The exploit allows for arbitrary code execution with the privileges of the InterBase service, and the payload is customizable via Metasploit's payload system. The code is written in Ruby and is structured as a standard Metasploit exploit module, making it weaponized and easily deployable within the Metasploit framework.
This repository contains a single Metasploit module (fb_isc_attach_database.rb) that exploits a stack buffer overflow vulnerability (CVE-2007-5243) in the Firebird and Borland InterBase database servers on Windows. The exploit works by sending a specially crafted database attach request to the service's default TCP port (3050), overflowing a stack buffer and injecting user-supplied shellcode. The module supports brute-forcing targets and includes hardcoded credentials (SYSDBA/masterkey) for authentication. The payload is customizable via Metasploit and typically results in remote code execution with system privileges. The code references a specific file path (unicode.nls) for targeting certain versions. The repository is structured as a standard Metasploit exploit module, written in Ruby, and is operational with customizable payload support.
This repository contains a single Metasploit exploit module targeting a stack buffer overflow vulnerability (CVE-2007-5243) in Borland InterBase and Firebird Relational Database on Windows. The exploit works by sending a specially crafted database creation request to the service's default TCP port (3050), triggering a buffer overflow and allowing execution of arbitrary code. The module supports multiple targets, including specific Firebird versions and a brute-force mode. The payload is customizable using Metasploit's payload system, with a default space of 512 bytes and bad character filtering. The exploit requires network access to the vulnerable service and leverages hardcoded credentials (SYSDBA/masterkey) for the database parameter block. The repository is structured as a single Ruby file compatible with the Metasploit framework, and is operational, providing remote code execution upon successful exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.