CVE-2004-2221
Mercantec SoftCart 4.00b - Remote Code Execution via Long HTTP GET Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2004-2221.
PoCs published by Metasploit, skape, skape, trew, including Metasploit module exploits/bsdi/softcart/mercantec_softcart.
AI-analyzed exploit summary This is a Metasploit module exploiting a buffer overflow in Mercantec SoftCart CGI (CVE-2004-2221) via a malformed HTTP GET request. It targets BSDi systems and uses brute-force to bypass ASLR-like protections.
Description
Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an HTTP GET request.
Exploits (3)
This is a Metasploit module exploiting a buffer overflow in Mercantec SoftCart CGI (CVE-2004-2221) via a malformed HTTP GET request. It targets BSDi systems and uses brute-force to bypass ASLR-like protections.
This exploit targets a buffer overflow in Mercantec SoftCart CGI (SoftCart.exe) via a malformed HTTP GET request. It includes a brute-force approach to bypass ASLR on BSDi systems and delivers a payload to achieve remote code execution.
This Metasploit module exploits a buffer overflow in Mercantec SoftCart CGI (SoftCart.exe) via a malformed HTTP GET request. It targets BSDi 4.3 systems and uses brute-force to bypass ASLR by spraying return addresses.