CVE-2002-0468

Ecartis 1.0.0 - Buffer Overflow via Long Command Line Argument

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2002-0468. PoCs published by the itch.

AI-analyzed exploit summary This exploit targets a local buffer overflow in Ecartis (formerly Listar) by overwriting the return address with a hardcoded stack address and executing shellcode to spawn a shell with setreuid(508). It relies on environment variables to pass the payload.

Description

Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files.

Exploits (2)

exploitdb WORKING POC VERIFIED
by the itch · clocallinux
https://www.exploit-db.com/exploits/21342

This exploit targets a local buffer overflow in Ecartis (formerly Listar) by overwriting the return address with a hardcoded stack address and executing shellcode to spawn a shell with setreuid(508). It relies on environment variables to pass the payload.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Ecartis (Listar) mailing list management software
No auth needed
Prerequisites: Local access to the system · Ecartis installed and running · Stack address may need adjustment
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by the itch · clocallinux
https://www.exploit-db.com/exploits/21341

This exploit targets a local buffer overflow in Ecartis (formerly Listar) version 0.129a. It overwrites the return address to execute shellcode, granting arbitrary code execution as the 'listar' user.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ecartis (Listar) 0.129a
No auth needed
Prerequisites: Local access to the target system · Ecartis (Listar) 0.129a installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Vendor Advisory mailing-list x_refsource_vuln-dev
http://online.securityfocus.com/archive/82/258763
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8445.php
Vendor Advisory mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/269879
Various Sources x_refsource_confirm
http://www.ecartis.org/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4271
Vendor Advisory mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/269658
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/261209

Scores

EPSS 0.0080
EPSS Percentile 51.6%

Details

Status published
Products (5)
ecartis/ecartis 1.0.0_snapshot_2002-01-21
ecartis/ecartis 1.0.0_snapshot_2002-01-25
listar/listar 0.126a
listar/listar 0.127a
listar/listar 0.129a
Published Aug 12, 2002
Tracked Since Feb 18, 2026