Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6838. PoCs published by Gregory R. Panakkal.
AI-analyzed exploit summary This exploit leverages an ActiveX control vulnerability in Rediff Bol Downloader to download and execute arbitrary files without proper filtering. It demonstrates the ability to spawn local executables (e.g., Notepad.exe) via the 'file://' protocol, bypassing IE security warnings for local files.
Description
Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter.
Exploits (1)
This exploit leverages an ActiveX control vulnerability in Rediff Bol Downloader to download and execute arbitrary files without proper filtering. It demonstrates the ability to spawn local executables (e.g., Notepad.exe) via the 'file://' protocol, bypassing IE security warnings for local files.