CVE-2002-1823

Zeroo HTTP Server 1.5 - Remote Code Execution via Long HTTP Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1823. PoCs published by dong-h0un U.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Zeroo HTTP Server, allowing remote code execution via a crafted HTTP request. It compiles and sends a bindshell payload to the target, then connects to the spawned shell on port 3879.

Description

Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary code via a long HTTP request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by dong-h0un U · bashremotelinux
https://www.exploit-db.com/exploits/22021

This exploit targets a buffer overflow vulnerability in Zeroo HTTP Server, allowing remote code execution via a crafted HTTP request. It compiles and sends a bindshell payload to the target, then connects to the spawned shell on port 3879.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zeroo HTTP Server
No auth needed
Prerequisites: Network access to the target server · Zeroo HTTP Server running on Linux
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6190
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10642.php
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/300066

Scores

EPSS 0.1051
EPSS Percentile 95.2%

Details

Status published
Products (1)
lonerunner/zeroo_http_server 1.5
Published Dec 31, 2002
Tracked Since Feb 18, 2026