CVE-2004-2530
Gadu-Gadu - Filename Extension Spoofing via Space Character Truncation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2530. PoCs published by Bartosz Kwitkowski.
AI-analyzed exploit summary This is a writeup describing a file extension obfuscation weakness in Gadu-Gadu, allowing attackers to disguise executable files as harmless by appending URL-encoded spaces and misleading text before the actual extension.
Description
Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with a large number of spaces followed by the real extension, which is not displayed in the dialog box.
Exploits (1)
This is a writeup describing a file extension obfuscation weakness in Gadu-Gadu, allowing attackers to disguise executable files as harmless by appending URL-encoded spaces and misleading text before the actual extension.