CVE-2008-1770

Akamai Download Manager <2.2.3.6 - CRLF Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1770. PoCs published by cocoruder.

AI-analyzed exploit summary This exploit leverages a vulnerability in Akamai Download Manager ActiveX control to download and execute a file from a remote server to an arbitrary location on the victim's system. The PoC specifically targets CVE-2008-1770 by manipulating the 'target' parameter to place the file in the Startup folder.

Description

CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line.

Exploits (1)

exploitdb WORKING POC VERIFIED
by cocoruder · htmlremotewindows
https://www.exploit-db.com/exploits/5741

This exploit leverages a vulnerability in Akamai Download Manager ActiveX control to download and execute a file from a remote server to an arbitrary location on the victim's system. The PoC specifically targets CVE-2008-1770 by manipulating the 'target' parameter to place the file in the Startup folder.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Akamai Download Manager v2.2.3 (ActiveX control)
No auth needed
Prerequisites: Victim must be using Internet Explorer with ActiveX enabled · Victim must visit the malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5741
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020194
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/493077/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30537
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42879
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2008-June/062672.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1746/references
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/493142/100/0/threaded

Scores

EPSS 0.1042
EPSS Percentile 95.2%

Details

CWE
CWE-94
Status published
Products (4)
akamai/download_manager 2.0.4.4
akamai/download_manager 2.2.0.0
akamai/download_manager 2.2.1.0
akamai/download_manager < 2.2.3.5
Published Jun 04, 2008
Tracked Since Feb 18, 2026