CVE-2004-1699

Pinnacle ShowCenter 1.51 - Denial of Service via Invalid Skin Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1699. PoCs published by Marc Ruef.

AI-analyzed exploit summary The exploit describes a denial of service vulnerability in Pinnacle Systems ShowCenter due to insufficient input validation on the 'Skin' parameter. Sending a malformed request to the 'SettingsBase.php' script with 'Skin=ATK' causes persistent denial of service.

Description

SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Marc Ruef · textdosphp
https://www.exploit-db.com/exploits/24621

The exploit describes a denial of service vulnerability in Pinnacle Systems ShowCenter due to insufficient input validation on the 'Skin' parameter. Sending a malformed request to the 'SettingsBase.php' script with 'Skin=ATK' causes persistent denial of service.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Pinnacle Systems ShowCenter
No auth needed
Prerequisites: Network access to the target web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109589167110196&w=2
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11232
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17463
Exploit, Vendor Advisory mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026733.html

Scores

EPSS 0.0810
EPSS Percentile 94.1%

Details

Status published
Products (1)
pinnacle_systems/showcenter 1.51
Published Sep 21, 2004
Tracked Since Feb 18, 2026