Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6396. PoCs published by Greg Linares.
AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in BlazeVideo HDTV Player <= v2.1 by crafting a malicious PLF file with an overly long path. It includes shellcode to execute calc.exe and provides multiple JMP ESP addresses for various Windows versions.
Description
Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist, a different product than CVE-2006-6199. NOTE: it was later reported that 3.5 is also affected.
Exploits (1)
This exploit demonstrates a stack-based buffer overflow in BlazeVideo HDTV Player <= v2.1 by crafting a malicious PLF file with an overly long path. It includes shellcode to execute calc.exe and provides multiple JMP ESP addresses for various Windows versions.