Spike is a well known http fuzzer. You could also look at some intercepting proxies other than Paros, such as Burp Suite and WebScarab, which don't modify the request in ways other than what you tell them to.
As for leveraging the bug to exploitation, have a read of some general buffer overflowing guides. Ive provided a few links to guides on this subject in a number of my previous posts, so hunt through my post history or search Google for results from this forum with my username and buffer overflow in them to find them.


