Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-3182. PoCs published by Shinnok, h07.
AI-analyzed exploit summary This exploit generates a malicious .m3u file that triggers a buffer overflow in Download Accelerator Plus (DAP) 8.x, allowing remote code execution via a crafted payload. It supports two payloads: a bind shell or an admin user addition, targeting Windows XP SP2/SP3.
Description
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allows user-assisted remote attackers to execute arbitrary code via an M3U (.m3u) file containing a long MP3 URL.
Exploits (2)
This exploit generates a malicious .m3u file that triggers a buffer overflow in Download Accelerator Plus (DAP) 8.x, allowing remote code execution via a crafted payload. It supports two payloads: a bind shell or an admin user addition, targeting Windows XP SP2/SP3.
This exploit targets a local buffer overflow in Download Accelerator Plus (DAP) 8.x via a maliciously crafted M3U file. It leverages a JMP ESP instruction in SHELL32.DLL to execute shellcode that launches calc.exe.