10
CVSSv2

CVE-2004-1120

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and previous versions allow remote servers to execute arbitrary code via a long Location header.

Vulnerable Product Search on Vulmon Subscribe to Product

prozilla prozilla download accelerator 1.3.5.1

prozilla prozilla download accelerator 1.3.5.2

prozilla prozilla download accelerator 1.0.0

prozilla prozilla download accelerator 1.3.0

prozilla prozilla download accelerator 1.3.6

prozilla prozilla download accelerator 1.3.3

prozilla prozilla download accelerator 1.3.4

prozilla prozilla download accelerator 1.3.5

prozilla prozilla download accelerator 1.3.1

prozilla prozilla download accelerator 1.3.2

Exploits

/* 20/10/2004 ** This is a private work of Serkan Akpolat deicide@siyahsapkaorg ** for the unpublished prozilla-136 format string/buffer overflow ** vulnerability , though this version only exploits the stack overflow ** Tested against current gentoo/slack/debian/suse with success :P ** Client side: proz hostname:port/anyfilename ** Default l ...