CVE-2005-0226
ngIRCd 0.8.2 - Remote Code Execution via Format String in Log_Resolver
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-0226. PoCs published by CoKi.
AI-analyzed exploit summary This exploit targets a format string vulnerability in ngIRCd <= 0.8.2, leveraging a fake ident server to trigger the vulnerability and execute shellcode for remote code execution. It includes brute-force capabilities for return address guessing and supports multiple target systems.
Description
Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.
Exploits (1)
This exploit targets a format string vulnerability in ngIRCd <= 0.8.2, leveraging a fake ident server to trigger the vulnerability and execute shellcode for remote code execution. It includes brute-force capabilities for return address guessing and supports multiple target systems.