Back

CVE-2005-1121

Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
igor_khasilev oops_proxy_server 1.4.22
igor_khasilev oops_proxy_server 1.5.19
igor_khasilev oops_proxy_server 1.5.53
gentoo linux *

GitHub Security Advisory GHSA-348c-hvj3-g7hp

Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 2.30%

Top 18% most likely to be exploited

Threat Score 20.7 / 100

Data Sources

NVD EPSS GitHub