EIP-2026-117286
PRE-CVEHTML Email Creator 2.1b668 - html Local Overwrite (SEH)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117286. PoCs published by dun.
AI-analyzed exploit summary This exploit demonstrates a local SEH overwrite vulnerability in HTML Email Creator <= 2.1 build 668 by crafting a malicious HTML file with an oversized 'src' attribute in an <img> tag. The payload includes a structured buffer with NOPs, a jump instruction, a pop-pop-ret address, and Metasploit-generated shellcode to execute 'calc.exe'.
Description
HTML Email Creator 2.1b668 - html Local Overwrite (SEH)
Exploits (1)
This exploit demonstrates a local SEH overwrite vulnerability in HTML Email Creator <= 2.1 build 668 by crafting a malicious HTML file with an oversized 'src' attribute in an <img> tag. The payload includes a structured buffer with NOPs, a jump instruction, a pop-pop-ret address, and Metasploit-generated shellcode to execute 'calc.exe'.