CVE-2007-3703
Zenturi Program Checker Pro - Stack-Based Buffer Overflow via Fill Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3703. PoCs published by callAX.
AI-analyzed exploit summary This exploit leverages a stack-based buffer overflow in the `Fill` method of `sasatl.dll` (v1.5.0.531) via JavaScript heap spraying to achieve remote code execution. The payload is delivered through an ActiveX control (CLSID: 7D6B5B29-FC7E-11D1-9288-00104B885781) and targets Internet Explorer on Windows XP/Vista.
Description
Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChecker) Pro allows remote attackers to execute arbitrary code via a long argument to the Fill method. NOTE: this is probably a different issue than CVE-2007-2987.
Exploits (1)
This exploit leverages a stack-based buffer overflow in the `Fill` method of `sasatl.dll` (v1.5.0.531) via JavaScript heap spraying to achieve remote code execution. The payload is delivered through an ActiveX control (CLSID: 7D6B5B29-FC7E-11D1-9288-00104B885781) and targets Internet Explorer on Windows XP/Vista.