10
CVSSv2

CVE-2004-1192

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in the lprintf function in Citadel/UX 6.27 and previous versions allows remote malicious users to execute arbitrary code via format string specifiers sent to the server.

Vulnerable Product Search on Vulmon Subscribe to Product

citadel ux 6.23

citadel ux 6.24

citadel ux 6.26

citadel ux 6.07

citadel ux 6.08

citadel ux 6.27

Exploits

/* citadel_fsexpc * * Citadel/UX v627 remote format string exploit * * Use: /citadel_fsexp -h <host> [options] * * options: * -h <arg> host or IP * -t <arg> type of target system * -l targets list * -g <arg> syslog GOT address * -r <arg> ...