9.3
CVSSv2

CVE-2006-3890

Published: 21/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote malicious users to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW object, a different vulnerability than CVE-2006-5198.

Vulnerable Product Search on Vulmon Subscribe to Product

sky software fileview activex control

winzip winzip 7.0

winzip winzip 8.0

winzip winzip

winzip winzip 8.1

winzip winzip 9.0

Exploits

<!-- prdelka blogs23nu/prdelka I made a version of my winzip exploit that utilises the heap spray method with a bindshell for some project or other you can download a copy here if its of use to you, note i used a different method courtesy of wwwmilw0rmcom/exploits/3055 - however i couldnt get their exploit to function en ...