EIP-2026-102872
PRE-CVEHTMLDOC 1.8.27 - '.html' File Handling Stack Buffer Overflow
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102872. PoCs published by Pankaj Kohli.
AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in HTMLDOC 1.8.27 by crafting a malicious HTML file that overwrites the return address with a 'push esp; ret' instruction, leading to execution of a port-binding shellcode (port 4444). The exploit is designed for Linux systems with ASLR enabled.
Description
HTMLDOC 1.8.27 - '.html' File Handling Stack Buffer Overflow
Exploits (1)
This exploit targets a stack-based buffer overflow in HTMLDOC 1.8.27 by crafting a malicious HTML file that overwrites the return address with a 'push esp; ret' instruction, leading to execution of a port-binding shellcode (port 4444). The exploit is designed for Linux systems with ASLR enabled.