CVE-2006-5650
America Online ICQ 5.1 - RCE
Title source: llmDescription
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16554
exploitdb
WORKING POC
VERIFIED
by Peter Vreugdenhil · rubyremotewindows
https://www.exploit-db.com/exploits/28916
metasploit
WORKING POC
EXCELLENT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/aol_icq_downloadagent.rb
References (8)
Scores
EPSS
0.8355
EPSS Percentile
99.3%
Details
Status
published
Products (1)
aol/icq
5.1
Published
Nov 07, 2006
Tracked Since
Feb 18, 2026