CVE-2002-1001

AnalogX Proxy - Buffer Overflow via Long HTTP Request or SOCKS 4A DNS Hostname

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1001. PoCs published by Kanatoko.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in AnalogX Proxy 4.10 via malformed SOCKS4A requests. It includes shellcode to execute 'notepad.exe' and leverages a JMP ESP address in user32.dll for Japanese Windows 2000 Pro SP2.

Description

Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A request to TCP port 1080 with a long DNS hostname.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kanatoko · perlremotewindows
https://www.exploit-db.com/exploits/21589

This exploit targets a buffer overflow vulnerability in AnalogX Proxy 4.10 via malformed SOCKS4A requests. It includes shellcode to execute 'notepad.exe' and leverages a JMP ESP address in user32.dll for Japanese Windows 2000 Pro SP2.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: AnalogX Proxy 4.10
No auth needed
Prerequisites: Network access to TCP port 1080 · Target running AnalogX Proxy 4.10 on Japanese Windows 2000 Pro SP2
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5139
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5138
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9456.php
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-07/0006.html
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9455.php

Scores

EPSS 0.0650
EPSS Percentile 92.9%

Details

Status published
Products (8)
analogx/proxy 4.0
analogx/proxy 4.0.1
analogx/proxy 4.0.2
analogx/proxy 4.0.3
analogx/proxy 4.0.4
analogx/proxy 4.0.5
analogx/proxy 4.0.6
analogx/proxy 4.0.7
Published Oct 04, 2002
Tracked Since Feb 18, 2026