EIP-2026-114950

PRE-CVE

Aurigma Image Uploader 4.x - ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114950. PoCs published by Elazar Broad.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in the Aurigma Image Uploader ActiveX control by passing an excessively long string to the GotoFolder and CanGotoFolder methods, potentially leading to arbitrary code execution in the context of Internet Explorer.

Description

Aurigma Image Uploader 4.x - ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by Elazar Broad · htmldoswindows
https://www.exploit-db.com/exploits/30797

This exploit targets a stack-based buffer overflow in the Aurigma Image Uploader ActiveX control by passing an excessively long string to the GotoFolder and CanGotoFolder methods, potentially leading to arbitrary code execution in the context of Internet Explorer.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Aurigma Image Uploader ActiveX control versions prior to 4.5.70
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer with the vulnerable ActiveX control installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026