CVE-1999-0744

Netscape Enterprise Server and FastTrack Server - Buffer Overflow via Long HTTP GET Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-1999-0744. PoCs published by Fyodor, Brock Tellier, ISS X-Force.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Netscape Enterprise Server 4.0 on SPARC/SunOS 5.7. It crafts a malicious GET request with shellcode to execute arbitrary commands, leveraging a super-dooper trick to retrieve the current address and execute a shell.

Description

Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Fyodor · perlremotesolaris
https://www.exploit-db.com/exploits/263

This exploit targets a buffer overflow vulnerability in Netscape Enterprise Server 4.0 on SPARC/SunOS 5.7. It crafts a malicious GET request with shellcode to execute arbitrary commands, leveraging a super-dooper trick to retrieve the current address and execute a shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Netscape Enterprise Server 4.0/sparc/SunOS 5.7
No auth needed
Prerequisites: Network access to the target server · Netscape Enterprise Server 4.0 running on SPARC/SunOS 5.7
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Brock Tellier · cremoteunixware
https://www.exploit-db.com/exploits/19705

This exploit targets a buffer overflow vulnerability in Netscape FastTrack Server 2.01a on UnixWare 7.1. It crafts a malicious HTTP GET request to overflow the stack and execute arbitrary shellcode, spawning an xterm with the privileges of the httpd (typically 'nobody').

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Netscape FastTrack Server 2.01a on UnixWare 7.1
No auth needed
Prerequisites: Network access to the target server on port 457 · Target running UnixWare 7.1 with vulnerable Netscape FastTrack Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ISS X-Force · textdoswindows
https://www.exploit-db.com/exploits/19783

This exploit demonstrates a buffer overflow vulnerability in Netscape Enterprise Server 3.6 by sending a GET request with over 4080 characters, causing httpd.exe to crash and potentially allowing remote code execution.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Netscape Enterprise Server 3.6
No auth needed
Prerequisites: Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/603

Scores

EPSS 0.0249
EPSS Percentile 82.6%

Details

Status published
Products (2)
netscape/enterprise_server
netscape/fasttrack_server
Published Jan 04, 2000
Tracked Since Feb 18, 2026