CVE-2008-0399
Toshiba Surveillix - Remote Code Execution via Long Arguments to SetPort or SetIpAddress Methods
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0399. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Toshiba Surveillance (Surveillix) RecordSend Class (MeIpCamX.DLL 1.0.0.4) via a maliciously crafted HTML page. It uses a heap spray technique to achieve remote code execution on Internet Explorer 7 with Windows XP SP2.
Description
Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Toshiba Surveillance (Surveillix) RecordSend Class (MeIpCamX.DLL 1.0.0.4) via a maliciously crafted HTML page. It uses a heap spray technique to achieve remote code execution on Internet Explorer 7 with Windows XP SP2.