Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4923. PoCs published by DeltahackingTEAM.
AI-analyzed exploit summary This exploit targets a vulnerability in the Aztec ActiveX control (MW6Aztec) by calling the SaveAsBMP method with a controlled filename, potentially leading to arbitrary file overwrite or code execution. The PoC demonstrates the issue by writing to a system file (system_.ini).
Description
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.
Exploits (1)
This exploit targets a vulnerability in the Aztec ActiveX control (MW6Aztec) by calling the SaveAsBMP method with a controlled filename, potentially leading to arbitrary file overwrite or code execution. The PoC demonstrates the issue by writing to a system file (system_.ini).