CVE-2008-6442

Sina Inc. DLoader Class ActiveX - File Overwrite

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6442. PoCs published by Symantec.

AI-analyzed exploit summary This exploit leverages a vulnerability in Sina DLoader to download and save malicious files to arbitrary locations on the affected system. The PoC uses an ActiveX control to trigger the download via the 'DownloadAndInstall' method.

Description

Insecure method vulnerability in Sina Inc. DLoader Class ActiveX Control allows remote attackers to overwrite arbitrary files via a URL in the first parameter to the DonwloadAndInstall method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Symantec · htmlremotewindows
https://www.exploit-db.com/exploits/32052

This exploit leverages a vulnerability in Sina DLoader to download and save malicious files to arbitrary locations on the affected system. The PoC uses an ActiveX control to trigger the download via the 'DownloadAndInstall' method.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Sina DLoader (version not specified)
No auth needed
Prerequisites: Victim must visit a malicious webpage · Sina DLoader must be installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43881
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30223

Scores

EPSS 0.0182
EPSS Percentile 75.9%

Details

Status published
Products (1)
sina/dloader
Published Mar 09, 2009
Tracked Since Feb 18, 2026