CVE-2001-0168
AT&T WinVNC < 3.3.3r7 - Remote Code Execution via Long HTTP GET Request
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2001-0168.
PoCs published by Metasploit, including Metasploit module exploits/windows/vnc/winvnc_http_get.
AI-analyzed exploit summary This exploit targets a buffer overflow in WinVNC Web Server <= v3.3.3r7 via an overly long GET request. It leverages stack-based overflow to execute arbitrary code, with specific return addresses for different Windows versions.
Description
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.
Exploits (2)
This exploit targets a buffer overflow in WinVNC Web Server <= v3.3.3r7 via an overly long GET request. It leverages stack-based overflow to execute arbitrary code, with specific return addresses for different Windows versions.
This Metasploit module exploits a buffer overflow in AT&T WinVNC's web server (v3.3.3r7 or earlier) via an overly long GET request when debugging mode with logging is enabled. It achieves remote code execution by overwriting the stack with a crafted payload and return address.