CVE-2002-1904
GazTek ghttpd 1.4-1.4.3 - Remote Code Execution via Long HTTP GET Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1904. PoCs published by qitest1.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in GazTek HTTP Daemon v1.4 (ghttpd) to achieve remote code execution. It uses a crafted HTTP GET request with shellcode to overflow the buffer and execute arbitrary commands with the privileges of the webserver.
Description
Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET request.
Exploits (1)
This exploit targets a buffer overflow vulnerability in GazTek HTTP Daemon v1.4 (ghttpd) to achieve remote code execution. It uses a crafted HTTP GET request with shellcode to overflow the buffer and execute arbitrary commands with the privileges of the webserver.