CVE-2004-2026
Pound <= 1.5 - Remote Code Execution via Format String in Logmsg Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2026. PoCs published by Nilanjan De.
AI-analyzed exploit summary This exploit targets a remote format string vulnerability in APSIS Pound <=1.5, allowing arbitrary code execution via crafted requests. It includes shellcode for a fork+portbind shell on port 31337 and supports both local and remote exploitation.
Description
Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.
Exploits (1)
This exploit targets a remote format string vulnerability in APSIS Pound <=1.5, allowing arbitrary code execution via crafted requests. It includes shellcode for a fork+portbind shell on port 31337 and supports both local and remote exploitation.