EIP-2026-114910
PRE-CVEAOL Products downloadUpdater2 Plugin - 'SRC' Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114910. PoCs published by rgod.
AI-analyzed exploit summary The exploit demonstrates a buffer overflow vulnerability in the AOL downloadUpdater2 Firefox plugin (npdnupdater2.dll v1.3.0.0) via an overlong 'SRC' parameter in an HTML embed tag. The PoC shows EIP control and a crash dump, with disassembly revealing the vulnerable copy loop and call to user-controlled memory.
Description
AOL Products downloadUpdater2 Plugin - 'SRC' Remote Code Execution
Exploits (1)
The exploit demonstrates a buffer overflow vulnerability in the AOL downloadUpdater2 Firefox plugin (npdnupdater2.dll v1.3.0.0) via an overlong 'SRC' parameter in an HTML embed tag. The PoC shows EIP control and a crash dump, with disassembly revealing the vulnerable copy loop and call to user-controlled memory.