9.3
CVSSv2

CVE-2008-4652

Published: 22/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote malicious users to execute arbitrary code via a long SecretKey property.

Vulnerable Product Search on Vulmon Subscribe to Product

dart powertcp ftp for activex 2.0.2.0

Exploits

<html> <pre> Author: Intel Discovered by: Intel Software: PowerTCP ActiveX Vulnerable Component: DartFtpdll Version: 2020 Website: wwwdartcom Description: "PowerTCP tools from Dart Communications are comprehensive tools you can include in your programs to perform common TCP/IP functions, including FTP, HTTP, SMTP, POP3, teln ...
<!-- PowerTCP FTP module Multiple Technique Exploit ( SEH Overwrite + HeapSpray ) bug originally found by : Intel (wwwmilw0rmcom/exploits/6793) I use Intel's exploit , but IE change unASCII bytes and it doesn't work! ( my system is XP SP2 IE7 ) then I wrote my own expl with HeapSpray technique , but it doesn't work again block of heap ...