A buffer overflow vulnerability exists in the Webster HTTP Server, where remote attackers can trigger a buffer overflow by sending a long URL in an HTTP request. This flaw allows for the execution of arbitrary code on the affected system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (kolibri_http.rb) that exploits a stack buffer overflow vulnerability in Kolibri HTTP Server version 2.0 (CVE-2002-2268). The exploit targets Windows XP SP3 and Windows Server 2003 SP2 platforms. It works by sending a specially crafted HTTP HEAD request to the server, overflowing a buffer in the request URI and overwriting the return address to execute an egghunter stub, which then locates and executes the attacker's payload. The payload is customizable and can be any Metasploit-supported Windows shellcode, up to 3000 bytes, with certain bad characters filtered. The module includes detection logic to fingerprint the Kolibri server and only attempts exploitation if the correct version is detected. The exploit is fully weaponized and integrated into the Metasploit framework, allowing for easy payload selection and execution.
This repository contains a single Metasploit module (modules/exploits/windows/http/webster_http.rb) that exploits a stack buffer overflow vulnerability in the Webster HTTP server, as described in CVE-2002-2268. The exploit targets the server by sending a specially crafted HTTP GET request with an overlong URI, triggering a buffer overflow and allowing execution of arbitrary code. The module is written in Ruby and leverages Metasploit's HttpClient and SEH exploitation mixins. The payload is customizable (up to 1024 bytes) and can be any standard Metasploit payload, such as a reverse shell. The exploit is operational and requires the attacker to have network access to the vulnerable server. The module references the original Microsoft Systems Journal article and the server's source code for context. No hardcoded IP addresses or hostnames are present; the exploit targets the root URI ("/") of the vulnerable HTTP server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.