Back
CVE-2005-0523
Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.
Published: May 2, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (9)
| Vendor | Product | Version |
|---|---|---|
| prozilla | prozilla_download_accelerator | 1.3.0 |
| prozilla | prozilla_download_accelerator | 1.3.1 |
| prozilla | prozilla_download_accelerator | 1.3.2 |
| prozilla | prozilla_download_accelerator | 1.3.3 |
| prozilla | prozilla_download_accelerator | 1.3.4 |
| prozilla | prozilla_download_accelerator | 1.3.5 |
| prozilla | prozilla_download_accelerator | 1.3.5.1 |
| prozilla | prozilla_download_accelerator | 1.3.5.2 |
| prozilla | prozilla_download_accelerator | 1.3.6 |
GitHub Security Advisory GHSA-hgg9-39pm-hm6w
Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute...
References (8)
- http://deicide.siyahsapka.org/exploits/proz_ex2.c
- http://www.debian.org/security/2005/dsa-719 Patch
- http://www.securiteam.com/exploits/5WP082KEUW.html Exploit
- http://www.securityfocus.com/bid/12635
- http://deicide.siyahsapka.org/exploits/proz_ex2.c
- http://www.debian.org/security/2005/dsa-719 Patch
- http://www.securiteam.com/exploits/5WP082KEUW.html Exploit
- http://www.securityfocus.com/bid/12635
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
9.87%
Top 5% most likely to be exploited
Threat Score
33 / 100
Data Sources
NVD
EPSS
GitHub