10
CVSSv2

CVE-2000-0010

Published: 26/12/1999 Updated: 17/08/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

WebWho+ whois.cgi program allows remote malicious users to execute commands via shell metacharacters in the TLD parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tony greenwood webwho\\+ 1.1

Exploits

source: wwwsecurityfocuscom/bid/892/info WebWho+ is a free cgi script written by Tony Greenwood for executing whois queries via the www Though it does perform checks for shell escape characters on some parameters, it misses the 'type' variable and allows for malicious input to be sent to a shell It is possible to execute arbitrary comma ...