CVE-2007-5604
HP Instant Support < 1.0.0.23 - Remote Code Execution via ExtractCab Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5604. PoCs published by Dennis Rand.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in HP Instant Support's HPISDataManager.dll ActiveX control. It uses a VBScript to trigger the vulnerability by passing an overly long string to the ExtractCab method, potentially leading to arbitrary code execution.
Description
Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5605, CVE-2007-5606, and CVE-2007-5607.
Exploits (1)
This exploit targets a buffer overflow vulnerability in HP Instant Support's HPISDataManager.dll ActiveX control. It uses a VBScript to trigger the vulnerability by passing an overly long string to the ExtractCab method, potentially leading to arbitrary code execution.