4458Third-party advisory
http://securityreason.com/securityalert/4458 CVE-2008-4652
Dart Communications PowerTCP FTP module - Remote Buffer Overflow
Record summary
CVE-2008-4652 has a selected CVSS score of 9.3; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBDart Communications PowerTCP FTP module - Remote Buffer OverflowExploitDB exploitby InTeLNot analyzed1 file
ExploitDBPowerTCP FTP Module - Multiple Techniques (SEH HeapSpray)ExploitDB exploitby Shahriyar JalayeriNot analyzed1 file
References
631814vdb entry
http://www.securityfocus.com/bid/31814 powertcp-ftp-activex-bo(45975)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45975 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-4652 6793exploit
https://www.exploit-db.com/exploits/6793 6840exploit
https://www.exploit-db.com/exploits/6840