CVE-2006-5650 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 67.1% (pctl 99)
Patch early
A public exploit exists.
Description
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 67.11% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-11-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| aol | icq |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | America Online ICQ - ActiveX Control Arbitrary File Download and Execute (Metasploit) | 2010-11-24 |
| exploit-db | America Online ICQ 5.1 - ActiveX Control Remote Code Execution | 2006-11-06 |
References
- http://secunia.com/advisories/22670
- http://securityreason.com/securityalert/1830
- http://securitytracker.com/id?1017163
- http://www.securityfocus.com/archive/1/450726/100/0/threaded
- http://www.securityfocus.com/bid/20930
- http://www.vupen.com/english/advisories/2006/4362
- http://www.zerodayinitiative.com/advisories/ZDI-06-037.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30059
- http://secunia.com/advisories/22670
- http://securityreason.com/securityalert/1830
- http://securitytracker.com/id?1017163
- http://www.securityfocus.com/archive/1/450726/100/0/threaded
- http://www.securityfocus.com/bid/20930
- http://www.vupen.com/english/advisories/2006/4362
- http://www.zerodayinitiative.com/advisories/ZDI-06-037.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30059
→ the Explorer · watch your stack · NVD