The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:27
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/1975 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/298 - |
Information
Published : 1997-07-15 04:00
Updated : 2024-11-20 23:27
NVD link : CVE-1999-0146
Mitre link : CVE-1999-0146
CVE.ORG link : CVE-1999-0146
JSON object : View
Products Affected
ncsa
- campas
- servers
CWE