CVE-2007-2668

webdesproxy 0.0.1 - Remote Code Execution via Long URL

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-2668. PoCs published by Xpl017Elz, vade79.

AI-analyzed exploit summary This exploit targets a buffer overflow in Webdesproxy 0.0.1 on Fedora Core 6, leveraging exec-shield bypass techniques to achieve remote code execution via a reverse shell. It constructs a malicious HTTP GET request to overwrite the GOT and execute arbitrary commands.

Description

Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involving the process_connection_request function in webdesproxy.c.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Xpl017Elz · cremotelinux
https://www.exploit-db.com/exploits/3922

This exploit targets a buffer overflow in Webdesproxy 0.0.1 on Fedora Core 6, leveraging exec-shield bypass techniques to achieve remote code execution via a reverse shell. It constructs a malicious HTTP GET request to overwrite the GOT and execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Webdesproxy 0.0.1
No auth needed
Prerequisites: Network access to the target · Webdesproxy service running on port 8080
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by vade79 · cremotewindows
https://www.exploit-db.com/exploits/3913

This exploit targets a remote buffer overflow in webdesproxy v0.0.1 via a crafted GET request, leveraging a static JMP ESP address in cygwin1.dll for reliable exploitation. It includes shellcode for a bind shell on port 7979.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: webdesproxy v0.0.1
No auth needed
Prerequisites: Network access to the target service · Cygwin1.dll with the expected JMP ESP address
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/40741
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23962
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1802
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3913

Scores

EPSS 0.0411
EPSS Percentile 89.5%

Details

CWE
CWE-119
Status published
Products (1)
webdesproxy/webdesproxy 0.0.1
Published May 14, 2007
Tracked Since Feb 18, 2026