CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
99.8%
Added: 05/17/2006
CVE: CVE-2004-1373
BID: 12096
OSVDB: 12585
SHOUTcast is a streaming audio server based on Winamp.
A format string vulnerability in SHOUTcast allows remote attackers to execute commands by requesting a MP3 filename containing format string characters such as **%n**
.
Upgrade to SHOUTcast 1.9.5 or higher.
<http://archives.neohapsis.com/archives/bugtraq/2004-12/0366.html>
Exploit works on SHOUTcast 1.9.4. The exploit may fail on servers using Security Enhanced Linux.
Windows 2000
Windows XP
Linux