CVE-2008-1933
Zune Software - Path Traversal and Arbitrary File Write via SaveToFile Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1933. PoCs published by ilion security.
AI-analyzed exploit summary This exploit leverages an arbitrary file overwrite vulnerability in the Zune software's EncProfile2 ActiveX control. By tricking a user into visiting a malicious page and authorizing the control, an attacker can overwrite arbitrary files on the system.
Description
Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the SaveToFile method. NOTE: the victim must explicitly allow the code to run.
Exploits (1)
This exploit leverages an arbitrary file overwrite vulnerability in the Zune software's EncProfile2 ActiveX control. By tricking a user into visiting a malicious page and authorizing the control, an attacker can overwrite arbitrary files on the system.