CVE-2004-1192
Citadel/UX <= 6.27 - Remote Code Execution via lprintf Format String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1192. PoCs published by CoKi.
AI-analyzed exploit summary This exploit leverages a format string vulnerability in Citadel/UX v6.27 to achieve remote code execution by overwriting the GOT entry of syslog with a controlled address. It uses a combination of format string manipulation and shellcode injection to spawn a reverse shell.
Description
Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.
Exploits (1)
This exploit leverages a format string vulnerability in Citadel/UX v6.27 to achieve remote code execution by overwriting the GOT entry of syslog with a controlled address. It uses a combination of format string manipulation and shellcode injection to spawn a reverse shell.