vendor:
NetSprint Toolbar
by:
Umesh Wanve
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: NetSprint Toolbar
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 2000 SP4 Server English, Windows 2000 SP4 Professional English
2007
NetSprint Toolbar ActiveX toolbar.dll DOS POC
This exploit targets the NetSprint Toolbar ActiveX toolbar.dll and causes a denial of service by crashing Internet Explorer. The vulnerability is due to the function ischecked() not properly handling a string parameter. When a parameter is supplied, IE crashes. Although data can be seen on the stack, it is difficult to exploit further. This proof-of-concept is provided for educational purposes only.
Mitigation:
No mitigation available.