CVE-2010-4597

Ecava IntegraXor < 3.5.3900.5 - Stack-Based Buffer Overflow via IntegraXor.Project ActiveX Control

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-4597. PoCs published by Jeremy Brown.

AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in Ecava IntegraXor's ActiveX control via the 'save' method, allowing arbitrary code execution by sending a maliciously crafted HTML page. The PoC triggers the vulnerability by passing an overly large string to the 'save' method, overwriting the return address.

Description

Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (HMI) before 3.5.3900.10 allows remote attackers to execute arbitrary code via a long string in the second argument.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jeremy Brown · pythondoswindows
https://www.exploit-db.com/exploits/15767

This exploit demonstrates a stack-based buffer overflow in Ecava IntegraXor's ActiveX control via the 'save' method, allowing arbitrary code execution by sending a maliciously crafted HTML page. The PoC triggers the vulnerability by passing an overly large string to the 'save' method, overwriting the return address.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ecava IntegraXor 3.5.3900.5
No auth needed
Prerequisites: Target must have Ecava IntegraXor 3.5.3900.5 installed · Target must access the malicious HTML page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42650
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/603928
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45487
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15767
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3275

Scores

EPSS 0.1882
EPSS Percentile 96.9%

Details

CWE
CWE-119
Status published
Products (1)
ecava/integraxor < 3.5.3900.5
Published Dec 23, 2010
Tracked Since Feb 18, 2026