CVE-2006-5650

America Online ICQ 5.1 - RCE

Title source: llm

Description

The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16554
exploitdb WORKING POC VERIFIED
by Peter Vreugdenhil · rubyremotewindows
https://www.exploit-db.com/exploits/28916
metasploit WORKING POC EXCELLENT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/aol_icq_downloadagent.rb

Scores

EPSS 0.8355
EPSS Percentile 99.3%

Details

Status published
Products (1)
aol/icq 5.1
Published Nov 07, 2006
Tracked Since Feb 18, 2026