CVE-2006-6133

Crystal Reports XI - Stack-based Buffer Overflow via Crafted RPT File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6133. PoCs published by LSsec.com.

AI-analyzed exploit summary The provided text describes a buffer overflow vulnerability in Business Objects Crystal Reports XI Professional, which can be exploited via a malicious document file to achieve arbitrary code execution. The actual exploit code is not included; only a reference to a binary exploit file is provided.

Description

Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.

Exploits (1)

exploitdb WRITEUP VERIFIED
by LSsec.com · textremotewindows
https://www.exploit-db.com/exploits/29171

The provided text describes a buffer overflow vulnerability in Business Objects Crystal Reports XI Professional, which can be exploited via a malicious document file to achieve arbitrary code execution. The actual exploit code is not included; only a reference to a binary exploit file is provided.

Classification
Writeup 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Business Objects Crystal Reports XI Professional
No auth needed
Prerequisites: Victim must open a malicious document file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017279
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3114
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30532
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2055
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26754
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23091
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4691
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-254A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21261
Various Sources x_refsource_misc
http://www.lssec.com/advisories/LS-20061102.pdf
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/452464/100/0/threaded

Scores

EPSS 0.7194
EPSS Percentile 98.8%

Details

CWE
CWE-119
Status published
Products (4)
businessobjects/crystal_reports_xi
microsoft/visual_studio_.net 2002 (2 CPE variants)
microsoft/visual_studio_.net 2003 (2 CPE variants)
microsoft/visual_studio_.net 2005 (2 CPE variants)
Published Nov 28, 2006
Tracked Since Feb 18, 2026