A buffer overflow vulnerability exists in Savant Web Server version 3.1 and earlier. The vulnerability is triggered when the server processes an overly long HTTP GET request, leading to a buffer overflow condition. This flaw allows remote attackers to overwrite memory and potentially execute arbitrary code on the affected system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a step-by-step exploit-development walkthrough for CVE-2002-1120, a stack-based buffer overflow in Savant Web Server 3.1. It is not part of a larger exploit framework; instead it is a standalone educational repository containing 14 Python 3 scripts and supporting Markdown documentation. The code is organized progressively under Vulnerability/Exploit/, starting with a simple connection test, then fuzzing, manual EIP offset discovery, EIP control validation, bad-character analysis for both the URI and HTTP method zones, gadget selection, landing verification, jump construction, HTTP body memory exploration, egghunter validation, and finally a full shellcode-bearing exploit. The exploit capability is remote code execution over the network via a crafted HTTP request to the Savant service on TCP port 80. The core exploit chain is: overflow the URI path at offset 267, overwrite EIP with a 3-byte POP EDI; RET gadget from Savant.exe at 0x0041e157, return into the attacker-controlled HTTP method field, execute a constrained conditional jump sequence in the method field because a normal short JMP opcode is filtered, land in the URI buffer where a NOP sled and egghunter reside, then scan memory for the egg tag w00tw00t placed in the HTTP body and jump to the final x86 shellcode stored there. This design is necessary because the URI buffer is too small to hold a full payload and the method field has a restrictive bad-character set. Notable technical findings embedded in the repository include: the vulnerable service is assumed at 127.0.0.1:80 by default; the EIP offset is 267 bytes; URI bad characters are documented as 0x00, 0x0a, 0x0d, and 0x3f; method-field bad characters are much broader and include lowercase letters and 0xe0-0xff; the method field is treated as executable; and the HTTP body is stored in a separate heap region, with an example located at 0x0247310F during debugging. The final exploit script contains a real shellcode blob and therefore goes beyond a pure proof of concept, but it is still relatively fixed and educational rather than highly modular or framework-driven, making OPERATIONAL the best maturity assessment.
This repository contains a single Metasploit module: 'modules/exploits/windows/http/savant_31_overflow.rb'. The module exploits a stack buffer overflow vulnerability in the Savant 3.1 Web Server running on Windows (including Windows 2000 and Windows XP). The exploit works by sending a specially crafted HTTP request with a malicious method string that overflows the server's buffer, allowing arbitrary code execution. The module is operational and allows the user to select a payload (with a size limit of 253 bytes and certain bad characters). The exploit is network-based and targets the root URI ('/'). The module includes logic to generate a safe NOP sled due to character mangling by the server. The exploit is limited by the server's thread count, allowing only 10 attempts on a default installation. The code is written in Ruby and is designed to be used within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.