CVE-2003-0510
ezbounce 1.0-1.50 - Remote Code Execution via Sessions Command Format String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-0510. PoCs published by V9.
AI-analyzed exploit summary This exploit targets a format string vulnerability in ezbounce (v1.04a to v1.50-pre6) via the 'sessions' command. It leverages user-controlled input in the nickname and server fields to overwrite the GOT entry of sscanf() and execute shellcode placed in __mbuffer[].
Description
Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.
Exploits (1)
This exploit targets a format string vulnerability in ezbounce (v1.04a to v1.50-pre6) via the 'sessions' command. It leverages user-controlled input in the nickname and server fields to overwrite the GOT entry of sscanf() and execute shellcode placed in __mbuffer[].