CVE-2008-4652
Dart PowerTCP FTP for ActiveX 2.0.2 - Buffer Overflow via Long SecretKey Property
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4652. PoCs published by Shahriyar Jalayeri, InTeL.
AI-analyzed exploit summary This exploit targets CVE-2008-4652 in the PowerTCP FTP module using a combination of SEH overwrite and heap spray techniques to achieve remote code execution. The exploit leverages a buffer overflow vulnerability to redirect execution to a controlled memory location containing shellcode.
Description
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property.
Exploits (2)
This exploit targets CVE-2008-4652 in the PowerTCP FTP module using a combination of SEH overwrite and heap spray techniques to achieve remote code execution. The exploit leverages a buffer overflow vulnerability to redirect execution to a controlled memory location containing shellcode.
This is a working exploit for CVE-2008-4652, targeting a buffer overflow vulnerability in PowerTCP ActiveX (DartFtp.dll). It uses a crafted buffer with a JMP ESP address and shellcode to execute arbitrary commands (calc.exe) via VBScript in Internet Explorer.