CVE-2007-1162
Common Controls Replacement Project BrowseDialog Server - Denial of Service via Long Property Value
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1162. PoCs published by shinnai.
AI-analyzed exploit summary This exploit demonstrates a Denial of Service (DoS) vulnerability in the BrowseDialog Class (ccrpbds6.dll) by passing excessively long strings to the IsFolderAvailable and RootFolder methods, likely causing a stack overflow. The PoC is written in VBScript and targets Internet Explorer 7 on Windows XP SP2.
Description
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder property value, different vectors than CVE-2007-0371.
Exploits (1)
This exploit demonstrates a Denial of Service (DoS) vulnerability in the BrowseDialog Class (ccrpbds6.dll) by passing excessively long strings to the IsFolderAvailable and RootFolder methods, likely causing a stack overflow. The PoC is written in VBScript and targets Internet Explorer 7 on Windows XP SP2.