CVE-2004-2120

reptile_web_server - Denial of Service via Incomplete GET Requests

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2120. PoCs published by Donato Ferrante.

AI-analyzed exploit summary The provided text describes a denial-of-service vulnerability in Reptile web server due to incomplete HTTP request handling. It instructs sending malformed GET requests without proper HTTP headers to trigger the issue.

Description

Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Donato Ferrante · textdosmultiple
https://www.exploit-db.com/exploits/23590

The provided text describes a denial-of-service vulnerability in Reptile web server due to incomplete HTTP request handling. It instructs sending malformed GET requests without proper HTTP headers to trigger the issue.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: Reptile web server
No auth needed
Prerequisites: Network access to the target web server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Vendor Advisory vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1008842
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=107497355713434&w=2
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9482
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/14932

Scores

EPSS 0.0306
EPSS Percentile 85.9%

Details

Status published
Products (1)
reptile_web_server/reptile_web_server 2002-01-05
Published Jan 23, 2004
Tracked Since Feb 18, 2026