7.5
CVSSv2

CVE-2005-0523

Published: 02/05/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in ProZilla 1.3.7.3 and previous versions allows remote malicious users to execute arbitrary code via format string specifiers in the Location header.

Vulnerable Product Search on Vulmon Subscribe to Product

prozilla prozilla download accelerator 1.3.5

prozilla prozilla download accelerator 1.3.5.2

prozilla prozilla download accelerator 1.3.6

prozilla prozilla download accelerator 1.3.0

prozilla prozilla download accelerator 1.3.1

prozilla prozilla download accelerator 1.3.2

prozilla prozilla download accelerator 1.3.3

prozilla prozilla download accelerator 1.3.4

prozilla prozilla download accelerator 1.3.5.1

Vendor Advisories

Several format string problems have been discovered in prozilla, a multi-threaded download accelerator, that can be exploited by a malicious server to execute arbitrary code with the rights of the user running prozilla For the stable distribution (woody) these problems have been fixed in version 136-3woody2 For the unstable distribution (sid) t ...

Exploits

/* ______ ________ \\___ \__\ ____/-- :::/ / \__________ \::: ::::/ / / |/ \:::: / / | \_ \ ______/ _ _ _________/ \___\\ \_________/ ::[ Electronic Souls ]:: ...