Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands.
Link | Tags |
---|---|
http://secunia.com/advisories/11299 | third party advisory |
http://www.osvdb.org/4966 | vdb entry |
http://securitytracker.com/id?1009667 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15742 | vdb entry |
http://www.securityfocus.com/bid/10053 | vdb entry exploit |
http://marc.info/?l=bugtraq&m=108120385811815&w=2 | mailing list |
http://aluigi.altervista.org/adv/igi2fs-adv.txt |