A stack-based buffer overflow exists in the connectHandle function in server.cpp in WebMod 0.48. The vulnerability is triggered when a remote attacker sends a long string in the Content-Length HTTP header, which is not properly checked for length before being copied to a stack buffer, allowing for overflow and potential control of execution flow.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone exploit PoC for CVE-2007-1260 affecting WebMod 0.48, a module used with Half-Life Dedicated Server (HLDS). It contains two files: a README describing the vulnerability, affected versions, exploitation notes, and suggested gadget locations; and a single C source file, w48crash.c, which is the actual exploit entry point. The exploit is a network-delivered stack buffer overflow triggered through an HTTP POST request. According to the README, WebMod allocates an 11-byte stack buffer for the Content-Length value but copies attacker-controlled data until newline/null without bounds checking. The PoC abuses this by connecting to a target host over TCP, defaulting to port 27015, and sending a crafted request beginning with "POST / HTTP/1.1\nHost: localhost:27015\nContent-Length: ". It then transmits a very large Content-Length field: seven 20,000-byte filler chunks plus 18,308 additional bytes to reach the saved return address, overwrites EIP with a hardcoded jmp esp address, appends shellcode, and terminates the header with two newlines. The code is clearly exploitative rather than merely demonstrative detection logic. It performs hostname resolution, socket creation, TCP connection, staged sending of the malicious request, and a delay to keep the socket open long enough for the target to receive the payload. The included payload is operational but not broadly portable: it is hardcoded Windows x86 shellcode intended for a specific Win2K SP4 environment with fixed API addresses. Its behavior is to display a MessageBox containing "HI!" and then terminate the process. The README also notes that setting the EIP value to 0xFFFFFFFF can be used to produce a crash-only denial of service. Overall, this is a genuine standalone exploit PoC with both DoS and RCE capability. Its structure is minimal, with one documentation file and one Windows C exploit source file. The main fingerprintable target characteristics are the HTTP POST handling path, the oversized Content-Length header, and the typical HLDS/WebMod listening port 27015.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.