Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6488. PoCs published by Kevin Finisterre.
AI-analyzed exploit summary This exploit targets a stack overflow vulnerability in the ICONICS Vessel/Gauge/Switch ActiveX controls (CVE-2006-6488) via a malicious HTML page. It uses heap spraying and a randomized JavaScript payload to achieve remote code execution.
Description
Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.
Exploits (1)
This exploit targets a stack overflow vulnerability in the ICONICS Vessel/Gauge/Switch ActiveX controls (CVE-2006-6488) via a malicious HTML page. It uses heap spraying and a randomized JavaScript payload to achieve remote code execution.