CVE-2010-2309

EvoLogical EvoCam 3.6.6-3.6.7 - Remote Code Execution via Long GET Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 5 public exploits for CVE-2010-2309. PoCs published by Metasploit, d1dn0t, Paul Harrington, dookie, including Metasploit module exploits/osx/http/evocam_webserver.

AI-analyzed exploit summary This is a functional Metasploit module exploiting a buffer overflow in the IRC client component of UFO: Alien Invasion 2.2.1. It crafts a malicious IRC server response to trigger a stack-based overflow, leading to arbitrary code execution on Mac OS X 10.5.8 x86 systems.

Description

Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary code via a long GET request.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteosx
https://www.exploit-db.com/exploits/16864

This is a functional Metasploit module exploiting a buffer overflow in the IRC client component of UFO: Alien Invasion 2.2.1. It crafts a malicious IRC server response to trigger a stack-based overflow, leading to arbitrary code execution on Mac OS X 10.5.8 x86 systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: UFO: Alien Invasion 2.2.1
No auth needed
Prerequisites: Network access to the target's IRC client port (6667 by default) · Target running UFO: Alien Invasion 2.2.1 on Mac OS X 10.5.8 x86
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteosx
https://www.exploit-db.com/exploits/16874

This exploit targets a stack buffer overflow in the EvoCam web server for Mac OS X, leveraging Dino Dai Zovi's exec-from-heap technique to execute arbitrary payloads. It is designed for versions 3.6.6 and 3.6.7, with specific offsets and memory addresses for reliable exploitation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EvoCam 3.6.6, 3.6.7
No auth needed
Prerequisites: Network access to the EvoCam web server on port 8080 · Vulnerable version of EvoCam installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by d1dn0t · pythonremoteosx
https://www.exploit-db.com/exploits/14254

This exploit targets a buffer overflow vulnerability in EvoCam Web Server for OSX versions 3.6.6 and 3.6.7. It uses ROP (Return-Oriented Programming) to bypass DEP and execute shellcode, resulting in remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: EvoCam Web Server OSX 3.6.6 and 3.6.7
No auth needed
Prerequisites: Network access to the target server · EvoCam Web Server running on OSX versions 3.6.6 or 3.6.7
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by d1dn0t · pythonremoteosx
https://www.exploit-db.com/exploits/13735

This exploit targets a buffer overflow vulnerability in EvoCam Web Server versions 3.6.6 and 3.6.7 on OS X 10.5.8. It sends a crafted HTTP GET request with a malicious payload to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EvoCam 3.6.6 and 3.6.7
No auth needed
Prerequisites: Network access to the target EvoCam web server · EvoCam version 3.6.6 or 3.6.7 running on OS X 10.5.8
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Paul Harrington, dookie · rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/http/evocam_webserver.rb

This Metasploit module exploits a stack buffer overflow in EvoCam's web server on Mac OS X, using a heap-based execution technique to achieve remote code execution. It targets specific versions of EvoCam (3.6.6 and 3.6.7) by sending a maliciously crafted HTTP GET request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EvoCam 3.6.6, 3.6.7 on Mac OS X
No auth needed
Prerequisites: Network access to the vulnerable EvoCam web server (port 8080) · Vulnerable version of EvoCam installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39988
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/40489
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/13735

Scores

EPSS 0.5084
EPSS Percentile 98.8%

Details

CWE
CWE-119
Status published
Products (2)
evological/evocam 3.6.6
evological/evocam 3.6.7
Published Jun 16, 2010
Tracked Since Feb 18, 2026