CVE-2001-0700

w3m < 0.2.1 - Remote Code Execution via Long Base64 Encoded MIME Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0700. PoCs published by White_E.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the w3m text-based browser (CVE-2001-0700) by sending a maliciously crafted MIME header with a base64-encoded string exceeding 32 characters. It includes shellcode to bind a shell on port 10000 and download/execute a backdoor from a specified URL.

Description

Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.

Exploits (1)

exploitdb WORKING POC VERIFIED
by White_E · perlremotefreebsd
https://www.exploit-db.com/exploits/20941

This exploit targets a buffer overflow vulnerability in the w3m text-based browser (CVE-2001-0700) by sending a maliciously crafted MIME header with a base64-encoded string exceeding 32 characters. It includes shellcode to bind a shell on port 10000 and download/execute a backdoor from a specified URL.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: w3m (versions prior to the fix for this vulnerability)
No auth needed
Prerequisites: Victim must connect to the malicious server using w3m · Network access to the victim's machine on port 10000
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000434
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2001/dsa-081
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2895
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6725
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2001/dsa-064
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/192371

Scores

EPSS 0.1263
EPSS Percentile 95.7%

Details

Status published
Products (9)
w3m/w3m 0.1.3
w3m/w3m 0.1.4
w3m/w3m 0.1.6
w3m/w3m 0.1.7
w3m/w3m 0.1.8
w3m/w3m 0.1.9
w3m/w3m 0.1.10
w3m/w3m 0.2
w3m/w3m < 0.2.1
Published Sep 20, 2001
Tracked Since Feb 18, 2026