gotfault.net
http://gotfault.net/research/advisory/gadv-powerd.txt CVE-2006-0681
Power Daemon 2.0.2 - 'WHATIDO' Remote Format String
Record summary
CVE-2006-0681 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPower Daemon 2.0.2 - 'WHATIDO' Remote Format StringExploitDB exploitby Gotfault SecurityNot analyzed1 file
References
618841Third-party advisory
http://secunia.com/advisories/18841 16582vdb entry
http://www.securityfocus.com/bid/16582 ADV-2006-0545vdb entry
http://www.vupen.com/english/advisories/2006/0545 powerdaemon-syslog-format-string(24713)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/24713 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-0681