CVE-1999-0744
Netscape Enterprise Server and FastTrack Server - Buffer Overflow via Long HTTP GET Request
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-1999-0744. PoCs published by Fyodor, Brock Tellier, ISS X-Force.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Netscape Enterprise Server 4.0 on SPARC/SunOS 5.7. It crafts a malicious GET request with shellcode to execute arbitrary commands, leveraging a super-dooper trick to retrieve the current address and execute a shell.
Description
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.
Exploits (3)
This exploit targets a buffer overflow vulnerability in Netscape Enterprise Server 4.0 on SPARC/SunOS 5.7. It crafts a malicious GET request with shellcode to execute arbitrary commands, leveraging a super-dooper trick to retrieve the current address and execute a shell.
This exploit targets a buffer overflow vulnerability in Netscape FastTrack Server 2.01a on UnixWare 7.1. It crafts a malicious HTTP GET request to overflow the stack and execute arbitrary shellcode, spawning an xterm with the privileges of the httpd (typically 'nobody').
This exploit demonstrates a buffer overflow vulnerability in Netscape Enterprise Server 3.6 by sending a GET request with over 4080 characters, causing httpd.exe to crash and potentially allowing remote code execution.