Record summary

CVE-2006-5820 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.

Description

The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary function pointer, which allows remote attackers to execute arbitrary code via a modified pointer value.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 3, 2008 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBAOL SuperBuddy - ActiveX Control Remote Code Execution (Metasploit)ExploitDB exploitby Krad ChadNot analyzed1 file
ExploitDB

PoC details

References

10