CVE-2007-5941
Adobe Shockwave Player - Stack-based Buffer Overflow via ShockwaveVersion Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5941. PoCs published by Elazar.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the Shockwave ActiveX control (SWCtl.SWCtl) by passing an excessively long string to the ShockwaveVersion method, leading to a denial-of-service (DoS) or potential remote code execution (RCE). The PoC uses JavaScript to trigger the vulnerability when the page loads.
Description
Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method.
Exploits (1)
This exploit targets a buffer overflow vulnerability in the Shockwave ActiveX control (SWCtl.SWCtl) by passing an excessively long string to the ShockwaveVersion method, leading to a denial-of-service (DoS) or potential remote code execution (RCE). The PoC uses JavaScript to trigger the vulnerability when the page loads.