Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4749. PoCs published by shinnai.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in db Software Laboratory VImpX (VImpX.ocx) v. 4.8.8.0, including a stack-based buffer overflow (RCE) and arbitrary file deletion/corruption via unsafe method calls. The PoC uses VBScript to trigger these vulnerabilities in Internet Explorer.
Description
Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in db Software Laboratory VImpX (VImpX.ocx) v. 4.8.8.0, including a stack-based buffer overflow (RCE) and arbitrary file deletion/corruption via unsafe method calls. The PoC uses VBScript to trigger these vulnerabilities in Internet Explorer.