CVE-2006-6026
Helix Server < 11.1.3 and Helix DNA Server 11.0-11.1 - Heap-Based Buffer Overflow via DESCRIBE Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6026. PoCs published by Winny Thomas.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Helix Server v11.0.1 via RTSP. It leverages a call dword ptr [eax + 4] instruction to redirect execution to shellcode, which binds a shell to port 4444.
Description
Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.0 and 11.1, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a DESCRIBE request that contains an invalid LoadTestPassword field.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Helix Server v11.0.1 via RTSP. It leverages a call dword ptr [eax + 4] instruction to redirect execution to shellcode, which binds a shell to port 4444.