PT-2004-2995 · Electronic Arts · Need For Speed Hot Pursuit 2.0
Luigi Auriemma
·
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2099
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Need for Speed Hot Pursuit 2.0 client (NFSHP2) versions 242 and earlier
Description
The issue allows remote attackers to execute arbitrary code via long commands, including
gamename, gamever, hostname, gametype, mapname, or gamemode.Recommendations
For versions 242 and earlier, update to a version later than 242 to resolve the issue. As a temporary workaround, consider restricting the length of the
gamename, gamever, hostname, gametype, mapname, and gamemode commands to prevent exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Need For Speed Hot Pursuit 2.0