10
CVSSv2

CVE-1999-1063

Published: 01/06/1999 Updated: 19/12/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

CDomain whois_raw.cgi whois CGI script allows remote malicious users to execute arbitrary commands via shell metacharacters in the fqdn parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cdomain cdomainfree 2.3

cdomain cdomainfree 2.4

cdomain cdomainfree 2.1

cdomain cdomainfree 2.2

cdomain cdomainfree 1.0

cdomain cdomainfree 2.0

Exploits

source: wwwsecurityfocuscom/bid/304/info A vulnerability in a CGI program part of CdomainFree allows remote malicious users to run any executable already existing to the machine The vulnerability is in the whois_rawcgi program This CGI passes user input to the shell without proper filtering None of the Cdomain commercial version (eg ...