7.5
CVSSv2

CVE-1999-0985

Published: 09/11/1999 Updated: 17/08/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CC Whois program whois.cgi allows remote malicious users to execute commands via shell metacharacters in the domain entry.

Vulnerable Product Search on Vulmon Subscribe to Product

cc cc whois 1.0

Exploits

source: wwwsecurityfocuscom/bid/2000/info Whois scripts provide InterNIC lookup services via HTTP The vulnerable scripts include versions of Matt's Whois and CGI City Whois Older versions of these fail to filter metacharacters, allowing execution of arbitrary commands by embedding the commands in the domain name to lookup Specifically, ...