7.5
CVSSv2

CVE-1999-0146

Published: 15/07/1997 Updated: 03/05/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The campas CGI program provided with some NCSA web servers allows an malicious user to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.

Vulnerable Product Search on Vulmon Subscribe to Product

ncsa campas

ncsa servers

Exploits

source: wwwsecurityfocuscom/bid/1975/info Campas is a sample CGI script shipped with some older versions of NCSA HTTPd, an obsolete web server package The versions that included the script could not be determined as the server is no longer maintained, but version 12 of the script itself is known to be vulnerable The script fails to pro ...