Vulnerabilities > CVE-2006-6488 - Remote Stack Buffer Overflow vulnerability in Iconics Dialog Wrapper Module Activex Control 8.4.165.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
iconics
exploit available

Summary

Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.

Vulnerable Configurations

Part Description Count
Application
Iconics
1

Exploit-Db

descriptionICONICS Vessel / Gauge / Switch 8.02.140 ActiveX BOF Exploit (meta). CVE-2006-6488. Remote exploit for windows platform
idEDB-ID:6570
last seen2016-02-01
modified2008-09-25
published2008-09-25
reporterKevin Finisterre
sourcehttps://www.exploit-db.com/download/6570/
titleICONICS Vessel / Gauge / Switch 8.02.140 - ActiveX BoF Exploit meta

Seebug

  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:65765
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-65765
    titleICONICS Vessel / Gauge / Switch 8.02.140 - ActiveX BOF Exploit (meta)
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:17367
    last seen2017-11-19
    modified2008-09-25
    published2008-09-25
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-17367
    titleICONICS Vessel / Gauge / Switch 8.02.140 ActiveX BOF Exploit (meta)