CVE-2010-2102
Description
Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.
In plain language
AI Worth attentionCVE-2010-2102 is a flaw in Webby Webserver 1.01 that lets an attacker send a very long web request to crash the server or potentially run malicious code—if you’re using Webby on a network, you should act now because there’s no known safe fix.
CVE-2010-2102 is a remotely triggerable buffer overflow in Webby Webserver 1.01 that allows a network attacker to send an oversized HTTP GET request (no authentication, no user interaction) to crash the service or execute arbitrary code; KEV listing is not present and no patch is known.
What to do now
- Check whether you are running Webby Webserver 1.01 (look in your server’s configuration, service name, and startup logs).
- If Webby Webserver 1.01 is in use and exposed to the network, stop the Webby service immediately.
- Restrict access so the server is not reachable from the public internet (allow only required internal IPs, or remove the public exposure).
- Replace Webby Webserver with a supported web server product/version that has active security support.
- Confirm after changes that the service is no longer reachable from external networks (test from outside your office network).
CVSS Vector Breakdown
AV:NAccess VectorAC:LAccess ComplexityAu:NAuthenticationC:CConfidentialityI:CIntegrityA:CAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2010-2102 and every CVE in our database. Create a free account — no credit card required.
Create Free Account