CVE-2001-0820

GazTek ghttpd 1.4 - Remote Code Execution via Long Arguments

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2001-0820. PoCs published by flea.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in GazTek HTTP Daemon v1.4 by sending a maliciously crafted GET request with an excessive argument length. It includes shellcode for a bind shell on port 36864 and supports multiple architectures (RedHat 7.2/7.3, Slackware 8.1).

Description

Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.

Exploits (2)

exploitdb WORKING POC VERIFIED
by flea · cremotelinux
https://www.exploit-db.com/exploits/21937

This exploit targets a stack-based buffer overflow in GazTek HTTP Daemon v1.4 by sending a maliciously crafted GET request with an excessive argument length. It includes shellcode for a bind shell on port 36864 and supports multiple architectures (RedHat 7.2/7.3, Slackware 8.1).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GazTek HTTP Daemon v1.4
No auth needed
Prerequisites: Network access to the target server · Target running GazTek HTTP Daemon v1.4 on a vulnerable architecture
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
cremotelinux
https://www.exploit-db.com/exploits/20929

This exploit targets a buffer overflow vulnerability in GazTek HTTP Daemon v1.4 (ghttpd) on Linux x86 systems. It crafts a malicious HTTP GET request with shellcode to achieve remote code execution, spawning a shell with the privileges of the webserver (typically 'nobody').

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GazTek HTTP Daemon v1.4 (ghttpd)
No auth needed
Prerequisites: Network access to the target server · Target running GazTek HTTP Daemon v1.4 on Linux x86
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2879
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2965
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=99279182704674&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6702
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=99406263214417&w=2

Scores

EPSS 0.3129
EPSS Percentile 96.9%

Details

Status published
Products (1)
gaztek/ghttp 1.4
Published Dec 06, 2001
Tracked Since Feb 18, 2026