Vulnerability record · CVE-2005-0478 · published 30 March 2005
CVE-2005-0478: TrackerCam buffer overflows via User-Agent header and PHP script arguments
Trackercam · Trackercam
TrackerCam 5.12 and earlier contain multiple buffer overflows reachable through HTTP requests, specifically a long User-Agent header and a long argument passed to an arbitrary PHP script. Successful exploitation can crash the service and may allow arbitrary code execution on the host.
Description
Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityThe vulnerability is remotely exploitable without authentication, has public exploit references, and a very high EPSS score, though the CVSS impact is limited to partial availability loss.
What it is
TrackerCam 5.12 and earlier contain multiple buffer overflows reachable through HTTP requests, specifically a long User-Agent header and a long argument passed to an arbitrary PHP script. Successful exploitation can crash the service and may allow arbitrary code execution on the host.
Impact
An attacker can cause a denial of service and potentially execute arbitrary code with the privileges of the web service. This could lead to full compromise of the affected system.
Attack surface
The flaws are reachable over the network via HTTP requests to the TrackerCam web interface. No authentication or user interaction is required, as indicated by the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Public exploit references are tagged Exploit and Vendor Advisory, and EPSS estimates a 66.5% probability of exploitation within 30 days (99.2nd percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild activity is recorded.
What to do
- Apply the vendor patch or upgrade TrackerCam beyond version 5.12 if an update is available.
- If no patch exists, isolate the TrackerCam service behind a reverse proxy or firewall that restricts access to trusted networks.
- Disable or remove unnecessary PHP scripts and limit the web server's exposure to the internet.
- Deploy a web application firewall or input filtering to reject overly long User-Agent headers and script arguments.
- Monitor vendor advisories for a fixed release and plan decommissioning of unsupported versions.
Detection
- Inspect web server and application logs for HTTP requests with abnormally long User-Agent headers.
- Monitor for requests to PHP scripts with unusually long or malformed query string arguments.
- Watch for repeated crashes or restarts of the TrackerCam service, which may indicate exploitation attempts.
- Use network monitoring to detect anomalous HTTP traffic patterns targeting the TrackerCam interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/archive/1/390918 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/12592 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/19409 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/19411 | |
| http://www.securityfocus.com/archive/1/390918 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/12592 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/19409 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/19411 |
Track CVE-2005-0478 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0478), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.