CVE-2004-1805
Unreal Engine 436 - Format String Vulnerability via Class Name Specifiers
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1805. PoCs published by Luigi Auriemma.
AI-analyzed exploit summary The provided text describes a format string vulnerability in the Unreal Tournament server engine, where unsanitized user-supplied network data can lead to arbitrary code execution. The example demonstrates a crash scenario by injecting format string specifiers into the 'Class' parameter.
Description
Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.
Exploits (1)
The provided text describes a format string vulnerability in the Unreal Tournament server engine, where unsanitized user-supplied network data can lead to arbitrary code execution. The example demonstrates a crash scenario by injecting format string specifiers into the 'Class' parameter.