10
CVSSv2

CVE-2000-0697

Published: 20/10/2000 Updated: 24/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

sun solaris answerbook2 1.3

sun solaris answerbook2 1.4

sun solaris answerbook2 1.4.1

sun solaris answerbook2 1.4.2

Exploits

source: wwwsecurityfocuscom/bid/1556/info A vulnerability exists in version 142 and prior of the AnswerBook2 server from Sun It is possible for remote users who have administrative access to execute arbitrary commands on the machine running AnswerBook2 These commands will be executed with the privileges of user 'daemon' One of the op ...