CVE-2007-2856
Dart Communications PowerTCP ZIP Compression ActiveX - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-2856. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Dart Communications PowerTCP ZIP Compression Control (DartZip.dll 1.8.5.3) via Internet Explorer 6. It uses a crafted HTML file with VBScript to trigger the overflow and execute shellcode that adds a user to the system.
Description
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855.
Exploits (2)
This exploit targets a buffer overflow vulnerability in Dart Communications PowerTCP ZIP Compression Control (DartZip.dll 1.8.5.3) via Internet Explorer 6. It uses a crafted HTML file with VBScript to trigger the overflow and execute shellcode that adds a user to the system.
This exploit targets a buffer overflow vulnerability in Dart Communications PowerTCP Service Control (DartService.dll 3.1.3.3) via Internet Explorer 6. It uses a crafted HTML file with VBScript to trigger the overflow and execute shellcode, adding a new administrator user.