CVE-2006-2439
ZipCentral < 4.01 - Stack-based Buffer Overflow via Long Filename in ZIP Archive
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2006-2439. PoCs published by Jiten Pathy, TecR0c, bratax.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in ZipCentral (CVE-2006-2439) by crafting a malicious ZIP file with an egghunter and alphanumeric shellcode to achieve remote code execution. The payload uses SEH overwrite techniques and custom decoding to bypass protections.
Description
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.
Exploits (3)
This exploit targets a buffer overflow vulnerability in ZipCentral (CVE-2006-2439) by crafting a malicious ZIP file with an egghunter and alphanumeric shellcode to achieve remote code execution. The payload uses SEH overwrite techniques and custom decoding to bypass protections.
This exploit targets a buffer overflow vulnerability in ZipCentral (CVE-2006-2439) by crafting a malicious .zip file with an oversized filename and embedded shellcode. It uses an egghunter technique to locate and execute the payload, achieving remote code execution on Windows XP SP3.
This exploit targets a buffer overflow vulnerability in ZipCentral 4.01 by crafting a malicious ZIP file. It uses SEH (Structured Exception Handler) overwrites and shellcode to achieve remote code execution, adding a user 'bck' with password 'bck'.