CVE-2006-5650
ICQ 5.1 - Remote Code Execution via ICQPhone.SipxPhoneManager ActiveX DownloadAgent Function
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2006-5650.
PoCs published by Metasploit, Peter Vreugdenhil, MC, including Metasploit module exploits/windows/browser/aol_icq_downloadagent.
AI-analyzed exploit summary This Metasploit module exploits CVE-2006-5650 by leveraging the ICQPhone.SipxPhoneManager ActiveX control to download and execute arbitrary files via the DownloadAgent function. It serves a malicious HTML page that triggers the vulnerability and delivers a payload executable.
Description
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.
Exploits (3)
This Metasploit module exploits CVE-2006-5650 by leveraging the ICQPhone.SipxPhoneManager ActiveX control to download and execute arbitrary files via the DownloadAgent function. It serves a malicious HTML page that triggers the vulnerability and delivers a payload executable.
This Metasploit module exploits a remote code execution vulnerability in the America Online ICQ ActiveX Control (CVE-2006-5650) by leveraging the DownloadAgent function to download and execute arbitrary files on a victim's system.
This Metasploit module exploits CVE-2006-5650 by leveraging the ICQPhone.SipxPhoneManager ActiveX control's DownloadAgent function to download and execute arbitrary files on a victim's system. It sets up an HTTP server to deliver a malicious EXE payload when the victim visits the crafted HTML page.