CVE-2008-0623
Yahoo! Music Jukebox 2.2.2.056 - Stack-Based Buffer Overflow via AddImage Method
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2008-0623. PoCs published by exceed, anonymous, h07.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Yahoo! Music Jukebox 2.2 via the AddImage() method in the ActiveX control. It uses heap spraying to execute shellcode (calc.exe) when the vulnerable method is triggered.
Description
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method.
Exploits (4)
This exploit targets a buffer overflow vulnerability in Yahoo! Music Jukebox 2.2 via the AddImage() method in the ActiveX control. It uses heap spraying to execute shellcode (calc.exe) when the vulnerable method is triggered.
This exploit targets a vulnerability in the Aurigma Image Uploader ActiveX control (CVE-2008-0624) by triggering a heap-based buffer overflow via a maliciously crafted AddImage method call. The exploit uses a heap spray technique to achieve reliable code execution.
This is a proof-of-concept exploit for a buffer overflow vulnerability in Yahoo! Music Jukebox 2.2. It leverages the AddImage() method in an ActiveX control to trigger a crash via a crafted URL, demonstrating potential for arbitrary code execution.
This is a functional exploit for a buffer overflow vulnerability in Yahoo! JukeBox's datagrid.dll AddButton() function. It uses heap spraying and shellcode to achieve remote code execution via a crafted HTML page.