CVE-2005-0788

LimeWire 4.1.2-4.5.6 - Arbitrary File Read via Gnutella GET Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-0788. PoCs published by lammat.

AI-analyzed exploit summary This exploit targets a directory traversal vulnerability in LimeWire versions 4.1.2 to 4.5.6, allowing remote attackers to read arbitrary files via a crafted HTTP request to the Gnutella service on port 6346. The script sends a malformed GET request with a traversal payload to retrieve the specified file.

Description

LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by lammat · perlremotemultiple
https://www.exploit-db.com/exploits/879

This exploit targets a directory traversal vulnerability in LimeWire versions 4.1.2 to 4.5.6, allowing remote attackers to read arbitrary files via a crafted HTTP request to the Gnutella service on port 6346. The script sends a malformed GET request with a traversal payload to retrieve the specified file.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: LimeWire 4.1.2 - 4.5.6
No auth needed
Prerequisites: Target running vulnerable LimeWire version · Network access to port 6346
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (4)

Core 4
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19693
Exploit, Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14555/
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111082448213238&w=2

Scores

EPSS 0.0692
EPSS Percentile 93.3%

Details

Status published
Products (2)
limewire/limewire 4.1.2
limewire/limewire 4.5.6
Published Mar 14, 2005
Tracked Since Feb 18, 2026