Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1074. PoCs published by Marsu.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in News Bin Pro 5.33 by crafting a malicious .nbi configuration file. The exploit overwrites the DataPath field with a payload that includes shellcode to execute arbitrary commands (e.g., calc.exe) via a controlled return address in MFC42.dll.
Description
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPath or (2) DownloadPath attributed in a (a) NBI file, or (3) a long group field in a (b) NZB file.
Exploits (1)
This exploit demonstrates a buffer overflow vulnerability in News Bin Pro 5.33 by crafting a malicious .nbi configuration file. The exploit overwrites the DataPath field with a payload that includes shellcode to execute arbitrary commands (e.g., calc.exe) via a controlled return address in MFC42.dll.