Back

CVE-2005-0188

Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.

Published: Oct 6, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
athoc athoc_toolbar *

GitHub Security Advisory GHSA-rrq9-69xh-wj7r

Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.69%

Top 15% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub