CVE-2008-1725

IBiz E-Banking Integrator <2.0.2932 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1725. PoCs published by shinnai.

AI-analyzed exploit summary This exploit targets an insecure method in IBiz E-Banking Integrator V2 ActiveX Edition, allowing arbitrary file creation via the WriteOFXDataFile method. The PoC demonstrates file creation on the local filesystem without authentication.

Description

The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe WriteOFXDataFile method, which allows remote attackers to overwrite arbitrary files via a full pathname in the argument. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/5416

This exploit targets an insecure method in IBiz E-Banking Integrator V2 ActiveX Edition, allowing arbitrary file creation via the WriteOFXDataFile method. The PoC demonstrates file creation on the local filesystem without authentication.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: IBiz E-Banking Integrator V2 ActiveX Edition
No auth needed
Prerequisites: ActiveX control must be installed and accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29758
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28700
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41752
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5416
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/44393

Scores

EPSS 0.0290
EPSS Percentile 85.1%

Details

Status published
Products (1)
nsoftware/ibiz_e-banking_integrator 2.0.2932
Published Apr 11, 2008
Tracked Since Feb 18, 2026