CVE-2005-2961

ProZilla Download Accelerator 1.3.7.4 - Buffer Overflow via FTP Search HREF Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-2961. PoCs published by taviso.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in ProZilla (CVE-2005-2961) by crafting a malicious ASP file with shellcode to execute arbitrary commands. The payload overwrites the return address and includes a NOP sled followed by shellcode to spawn a shell.

Description

Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers to execute arbitrary code via a search response with a crafted string in the HREF field of an <A> tag.

Exploits (1)

exploitdb WORKING POC VERIFIED
by taviso · cremotelinux
https://www.exploit-db.com/exploits/1238

This exploit targets a buffer overflow vulnerability in ProZilla (CVE-2005-2961) by crafting a malicious ASP file with shellcode to execute arbitrary commands. The payload overwrites the return address and includes a NOP sled followed by shellcode to spawn a shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ProZilla (version not specified)
No auth needed
Prerequisites: Ability to write a file to the target system · Target system must be running vulnerable ProZilla software
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-834
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17035
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14993
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17021/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/22491

Scores

EPSS 0.0862
EPSS Percentile 94.4%

Details

Status published
Products (1)
prozilla/prozilla_download_accelerator 1.3.7.4
Published Oct 05, 2005
Tracked Since Feb 18, 2026