CVE-2003-1174
NullSoft Shoutcast Server 1.9.2 - Denial of Service via Long icy-name or icy-url Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2003-1174. PoCs published by exworm, airsupply.
AI-analyzed exploit summary This exploit targets a memory corruption vulnerability in Nullsoft SHOUTcast Server 1.9.2, leveraging insufficient bounds checking in the icy-name and icy-url commands to achieve remote code execution via a connect-back shellcode payload.
Description
Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL.
Exploits (2)
This exploit targets a memory corruption vulnerability in Nullsoft SHOUTcast Server 1.9.2, leveraging insufficient bounds checking in the icy-name and icy-url commands to achieve remote code execution via a connect-back shellcode payload.
This exploit targets a memory corruption vulnerability in Nullsoft SHOUTcast Server 1.9.2 by sending a maliciously crafted icy-name header with shellcode to achieve remote code execution. It establishes a reverse shell on port 5074 after triggering the vulnerability.