9.3
CVSSv2

CVE-2007-2856

Published: 24/05/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote malicious users to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855.

Vulnerable Product Search on Vulmon Subscribe to Product

dart powertcp_zip_compression 1.8.5.3

Exploits

<!-- IE 6 / Dart Communications PowerTCP Service Control (DartServicedll 3133) remote buffer overflow exploit / xp sp2 ita ver by rgod site: retrogodaltervistaorg software site: wwwdartcom Install, Uninstall methods are vulnerable shellcode is executed after the browser window is closed, no crash more chars cause an heap overflow Somet ...
<!-- IE 6 / Dart Communications PowerTCP ZIP Compression Control (DartZipdll 1853) remote buffer overflow exploit / xp sp2 it by rgod site: retrogodaltervistaorg software site: wwwdartcom --> <html> <object classid='clsid:42BA826E-F8D8-4D8D-8C05-14ABCE99D4DD' id='DartZip'></object> <script language='vbscript'> ...