CVE-2002-0142
pi3web 2.0 beta 1 and 2 - Denial of Service via Long Physical Path with Trailing Dots
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0142. PoCs published by aT4r.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Pi3Web 2.0.1 by sending a malformed HTTP GET request with an excessively long path (354 slashes). The exploit causes a denial of service (DoS) by crashing the web server.
Description
CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whose physical path is exactly 260 characters long and ends in a series of . (dot) characters.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Pi3Web 2.0.1 by sending a malformed HTTP GET request with an excessively long path (354 slashes). The exploit causes a denial of service (DoS) by crashing the web server.