Vulnerability Name: | CVE-1999-0146 (CCN-298) | ||||||||
Assigned: | 1997-07-15 | ||||||||
Published: | 1997-07-15 | ||||||||
Updated: | 2018-05-03 | ||||||||
Summary: | The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-1999-0146 Source: CCN Type: BugTraq Mailing List, 1997-07-15 18:24:31 Bug CGI campas Source: CCN Type: OSVDB ID: 29 NCSA Campas cgi-bin Arbitrary Command Execution Source: BID Type: UNKNOWN 1975 Source: CCN Type: BID-1975 NCSA HTTPd campas sample script Vulnerability Source: XF Type: UNKNOWN http-cgi-campas(298) Source: XF Type: UNKNOWN http-cgi-campas(298) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |