Vulnerabilities > CVE-2006-5198 - Unspecified vulnerability in Winzip 10.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | WinZip FileView (WZFILEVIEW.FileViewCtrl.61) ActiveX Buffer Overflow. CVE-2006-5198. Remote exploit for windows platform |
id | EDB-ID:16607 |
last seen | 2016-02-02 |
modified | 2010-04-30 |
published | 2010-04-30 |
reporter | metasploit |
source | https://www.exploit-db.com/download/16607/ |
title | WinZip FileView WZFILEVIEW.FileViewCtrl.61 ActiveX Buffer Overflow |
Metasploit
description | The FileView ActiveX control (WZFILEVIEW.FileViewCtrl.61) could allow a remote attacker to execute arbitrary code on the system. The control contains several unsafe methods and is marked safe for scripting and safe for initialization. A remote attacker could exploit this vulnerability to execute arbitrary code on the victim system. WinZip 10.0 <= Build 6667 are vulnerable. |
id | MSF:EXPLOIT/WINDOWS/BROWSER/WINZIP_FILEVIEW |
last seen | 2020-03-23 |
modified | 2017-07-24 |
published | 2009-03-15 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5198 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/browser/winzip_fileview.rb |
title | WinZip FileView (WZFILEVIEW.FileViewCtrl.61) ActiveX Buffer Overflow |
Nessus
NASL family | Windows |
NASL id | WINZIP_FILEVIEW_ACTIVEX_CODE_EXEC.NASL |
description | The remote host contains a version of the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 23648 |
published | 2006-11-15 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/23648 |
title | WinZip FileView ActiveX Control Vulnerabilities |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/83024/winzip_fileview.rb.txt |
id | PACKETSTORM:83024 |
last seen | 2016-12-05 |
published | 2009-11-26 |
reporter | dean |
source | https://packetstormsecurity.com/files/83024/WinZip-FileView-WZFILEVIEW.FileViewCtrl.61-ActiveX-Buffer-Overflow.html |
title | WinZip FileView (WZFILEVIEW.FileViewCtrl.61) ActiveX Buffer Overflow |
Saint
bid | 21060 |
description | WinZip FileView ActiveX control unsafe method |
id | misc_compress_winzip |
osvdb | 30433 |
title | winzip_fileview |
type | client |
References
- http://isc.sans.org/diary.php?storyid=1861
- http://isc.sans.org/diary.php?storyid=1861
- http://secunia.com/advisories/22891
- http://secunia.com/advisories/22891
- http://securitytracker.com/id?1017226
- http://securitytracker.com/id?1017226
- http://www.kb.cert.org/vuls/id/512804
- http://www.kb.cert.org/vuls/id/512804
- http://www.securityfocus.com/archive/1/451589/100/0/threaded
- http://www.securityfocus.com/archive/1/451589/100/0/threaded
- http://www.securityfocus.com/bid/21060
- http://www.securityfocus.com/bid/21060
- http://www.vupen.com/english/advisories/2006/4509
- http://www.vupen.com/english/advisories/2006/4509
- http://www.winzip.com/wz7245.htm
- http://www.winzip.com/wz7245.htm
- http://www.zerodayinitiative.com/advisories/ZDI-06-040.html
- http://www.zerodayinitiative.com/advisories/ZDI-06-040.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067