10
CVSSv2

CVE-2004-0524

Published: 06/08/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the chpasswd command in the Change_passwd plugin prior to 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

/* ** PST_chpasswd_exp-v_bc: ** ** Squirrelmail chpasswd local root bruteforce exploit ** Author: ** Bytes<Bytes[at]ph4nt0mnet> || <Bytes[at]ph4nt0morg> ** www ph4nt0m net ** Notice: ** v_b: Local bruteforce version ** v_R: remote bruteforce version ** ** ** Greatze: #ph4nt0m,#music@0x557 ** All PST member,Grip2,Airsupp ...
/* * 0x3142-sq-chpasswdc * Squirremail chpasswd buffer overflow * * Tested on SuSE 9 * The bug was found by Matias Neiff <matias neiff com ar> * Coded by x314 <0x3142 hushmailcom> * (c) 2004 Copyright by x314 * All Rights Reserved * * Greets: m0s krewz * */ #include <stdlibh> char shellcode[]= "\x31\xc0\xb0\x46\x31\xdb\ ...