CVE-2004-1120

ProZilla Download Accelerator <= 1.3.6-r2 - Remote Code Execution via Long Location Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1120. PoCs published by Serkan Akpolat.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in prozilla-1.3.6, sending a crafted HTTP response to trigger a stack overflow and execute shellcode. The shellcode establishes a reverse shell connection to the attacker's specified IP and port.

Description

Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Serkan Akpolat · cremotelinux
https://www.exploit-db.com/exploits/652

This exploit targets a buffer overflow vulnerability in prozilla-1.3.6, sending a crafted HTTP response to trigger a stack overflow and execute shellcode. The shellcode establishes a reverse shell connection to the attacker's specified IP and port.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: prozilla-1.3.6
No auth needed
Prerequisites: Network access to the target · Target must be running prozilla-1.3.6
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Issue Tracking x_refsource_confirm
http://bugs.gentoo.org/show_bug.cgi?id=70090
Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200411-31.xml
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-663
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18210
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11734
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/382219

Scores

EPSS 0.1464
EPSS Percentile 96.2%

Details

Status published
Products (10)
prozilla/prozilla_download_accelerator 1.0.0
prozilla/prozilla_download_accelerator 1.3.0
prozilla/prozilla_download_accelerator 1.3.1
prozilla/prozilla_download_accelerator 1.3.2
prozilla/prozilla_download_accelerator 1.3.3
prozilla/prozilla_download_accelerator 1.3.4
prozilla/prozilla_download_accelerator 1.3.5
prozilla/prozilla_download_accelerator 1.3.5.1
prozilla/prozilla_download_accelerator 1.3.5.2
prozilla/prozilla_download_accelerator 1.3.6
Published Jan 10, 2005
Tracked Since Feb 18, 2026