CVE-2008-0631
MailBee Objects 5.5 - Arbitrary File Write via SaveToDisk Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0631. PoCs published by darkl0rd.
AI-analyzed exploit summary This exploit leverages insecure methods in MailBee Objects v5.5 (MailBee.dll) to save files to arbitrary locations on the system. It uses VBScript to trigger the SaveToDisk and AddStringToFile methods via ActiveX controls, demonstrating file creation and overwriting capabilities.
Description
Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or (2) modify files via the AddStringToFile method.
Exploits (1)
This exploit leverages insecure methods in MailBee Objects v5.5 (MailBee.dll) to save files to arbitrary locations on the system. It uses VBScript to trigger the SaveToDisk and AddStringToFile methods via ActiveX controls, demonstrating file creation and overwriting capabilities.