CVE-2004-1120
ProZilla Download Accelerator <= 1.3.6-r2 - Remote Code Execution via Long Location Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1120. PoCs published by Serkan Akpolat.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in prozilla-1.3.6, sending a crafted HTTP response to trigger a stack overflow and execute shellcode. The shellcode establishes a reverse shell connection to the attacker's specified IP and port.
Description
Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header.
Exploits (1)
This exploit targets a buffer overflow vulnerability in prozilla-1.3.6, sending a crafted HTTP response to trigger a stack overflow and execute shellcode. The shellcode establishes a reverse shell connection to the attacker's specified IP and port.