vendor:
ImageShack Toolbar
by:
Rew
7,5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: ImageShack Toolbar
Affected Version From: 4.8.3.75
Affected Version To: 4.8.3.75
Patch Exists: NO
Related CWE: NA (0day)
CPE: a:imageshack:imageshack_toolbar
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WinXP - IE 6 & 7
2010
ImageShack Toolbar 4.8.3.75 Remote Code Execution Exploit
ImageShack Toolbar 4.8.3.75 is vulnerable to a remote code execution exploit. The exploit involves setting two vulnerable variables to some integer, which is then stored (in hex) directly in ECX. The attacker then sprays the heap and puts something useful in ECX. This exploit is not marked safe for scripting, so the impact of this issue is small.
Mitigation:
Change ActiveX settings to let it run.