7.5
CVSSv2

CVE-1999-0947

Published: 02/11/1999 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote malicious users to execute commands via shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

an an-httpd 1.2b

Exploits

source: wwwsecurityfocuscom/bid/762/info Certain versions of the AN-HTTPd server contain default CGI scripts that allow code to be executed remotely This is due to poor sanity checking on user supplied data wwwxxxyy/cgi-bin/inputbat?|dir\\windows ...