CVE-2006-6288

Niek Albers CoolPlayer <216 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6288. PoCs published by Trancek.

AI-analyzed exploit summary This exploit targets a local buffer overflow in CoolPlayer 2.17 via a maliciously crafted .m3u playlist file. It uses a JMP ESP instruction from ntdll.dll (Windows XP SP2 Spanish) and includes Metasploit-generated shellcode for a bind shell on port 4444.

Description

Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via (1) a playlist file with long song names, because of an overflow in the CPL_AddPrefixedFile function in CPI_Playlist.c; (2) a skin file with long button names, because of an overflow in the main_skin_check_ini_value function in skin.c; and (3) a skin file with long bitmap filenames, because of an overflow in the main_skin_open function in skin.c.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Trancek · perllocalwindows
https://www.exploit-db.com/exploits/4839

This exploit targets a local buffer overflow in CoolPlayer 2.17 via a maliciously crafted .m3u playlist file. It uses a JMP ESP instruction from ntdll.dll (Windows XP SP2 Spanish) and includes Metasploit-generated shellcode for a bind shell on port 4444.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CoolPlayer 2.17
No auth needed
Prerequisites: Victim must open the crafted .m3u file in CoolPlayer 2.17 · Attacker must know the target's directory path length for proper offset calculation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (13)

Core 13
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30863
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4806
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30861
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30658
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23360
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/485547/100/100/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4839
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/485564/100/100/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/485578/100/100/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21396

Scores

EPSS 0.0655
EPSS Percentile 92.9%

Details

CWE
CWE-119
Status published
Products (1)
niek_albers/coolplayer < 216
Published Dec 04, 2006
Tracked Since Feb 18, 2026