EIP-2026-118501
PRE-CVEEDraw Office Viewer 5.4 - 'HttpDownloadFile()' Insecure Method
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118501. PoCs published by Cyber-Zone.
AI-analyzed exploit summary This exploit targets an insecure method in Edraw Office Viewer Component v5.4, specifically the HttpDownloadFile() function, which allows arbitrary file download to the victim's system. The PoC uses VBScript to trigger the download of a file from a remote server to a local path.
Description
EDraw Office Viewer 5.4 - 'HttpDownloadFile()' Insecure Method
Exploits (1)
This exploit targets an insecure method in Edraw Office Viewer Component v5.4, specifically the HttpDownloadFile() function, which allows arbitrary file download to the victim's system. The PoC uses VBScript to trigger the download of a file from a remote server to a local path.