CVE-2004-1286

NapShare 1.2 - Buffer Overflow via Gnutella Response

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-1286. PoCs published by Bartlomiej Sieka.

AI-analyzed exploit summary This exploit targets a buffer overflow in NapShare 1.2 by sending a maliciously crafted Gnutella server response. It leverages the 'extern' filter in the automation feature to trigger arbitrary command execution via a system(3) call.

Description

Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows remote attackers to execute arbitrary code via a crafted gnutella response.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Bartlomiej Sieka · cremotelinux
https://www.exploit-db.com/exploits/24857

This exploit targets a buffer overflow in NapShare 1.2 by sending a maliciously crafted Gnutella server response. It leverages the 'extern' filter in the automation feature to trigger arbitrary command execution via a system(3) call.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NapShare 1.2
No auth needed
Prerequisites: Network access to the target · Target must connect to a malicious Gnutella server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Bartlomiej Sieka · cremotelinux
https://www.exploit-db.com/exploits/24856

This exploit targets a buffer overflow vulnerability in NapShare 1.2 by sending a maliciously crafted Gnutella server response. It includes shellcode to create a file named 'EXPLOIT' as a proof of arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NapShare 1.2
No auth needed
Prerequisites: Network access to the target · Target must connect to a malicious Gnutella server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Vendor Advisory x_refsource_misc
http://tigger.uic.edu/~jlongs2/holes/napshare.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18630

Scores

EPSS 0.1240
EPSS Percentile 95.7%

Details

Status published
Products (1)
napshare/napshare 1.2
Published Jan 10, 2005
Tracked Since Feb 18, 2026