CVE-2008-4924
MW6 Technologies 1D Barcode ActiveX control <3.0.0.1 - Code Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4924. PoCs published by DeltahackingTEAM.
AI-analyzed exploit summary This exploit targets a vulnerability in the MW6 Barcode ActiveX control (version 3.0.0.1) by leveraging unsafe file write operations in the SaveAsBMP method. It demonstrates arbitrary file creation by writing to a system file (system_.ini) via a crafted argument.
Description
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.
Exploits (1)
This exploit targets a vulnerability in the MW6 Barcode ActiveX control (version 3.0.0.1) by leveraging unsafe file write operations in the SaveAsBMP method. It demonstrates arbitrary file creation by writing to a system file (system_.ini) via a crafted argument.