CVE-2008-6737
Crysis < 1.21 - Unauthenticated Exposure of Sensitive Player Information via Keyexchange Packet
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6737. PoCs published by Luigi Auriemma.
AI-analyzed exploit summary The provided entry describes an information-disclosure vulnerability in Crysis 1.21 and prior versions, attributed to a design error. No exploit code is included; only a reference to a binary exploit (31918.zip) is provided.
Description
Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information.
Exploits (1)
The provided entry describes an information-disclosure vulnerability in Crysis 1.21 and prior versions, attributed to a design error. No exploit code is included; only a reference to a binary exploit (31918.zip) is provided.