Record summary

CVE-2004-2026 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBAPSIS Pound 1.5 - Remote Format StringExploitDB exploitby Nilanjan DeNot analyzed1 file
ExploitDB

PoC details

References

9