EIP-2026-114739
PRE-CVEInso DynaWeb HTTPd 3.1/4.0.2/4.1 - Format String
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114739. PoCs published by ghandi.
AI-analyzed exploit summary This exploit targets a format string vulnerability in the DynaWeb HTTPD (dwhttpd) server, specifically in the nsapi_log_error() function. It bypasses authentication to retrieve a stack pointer from the error log and calculates the location of shellcode to execute arbitrary code, binding a shell to port 2001.
Description
Inso DynaWeb HTTPd 3.1/4.0.2/4.1 - Format String
Exploits (1)
This exploit targets a format string vulnerability in the DynaWeb HTTPD (dwhttpd) server, specifically in the nsapi_log_error() function. It bypasses authentication to retrieve a stack pointer from the error log and calculates the location of shellcode to execute arbitrary code, binding a shell to port 2001.