CVE-2000-0670

The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharacters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cvsweb_developer:cvsweb:1.80:*:*:*:*:*:*:*

History

20 Nov 2024, 23:33

Type Values Removed Values Added
References () ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:37.cvsweb.asc - () ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:37.cvsweb.asc -
References () http://archives.neohapsis.com/archives/bugtraq/2000-07/0178.html - () http://archives.neohapsis.com/archives/bugtraq/2000-07/0178.html -
References () http://archives.neohapsis.com/archives/bugtraq/2000-07/0196.html - Exploit, Patch, Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2000-07/0196.html - Exploit, Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/1469 - () http://www.securityfocus.com/bid/1469 -
References () http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000015.html - () http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000015.html -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/4925 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/4925 -

Information

Published : 2000-07-12 04:00

Updated : 2025-04-03 01:03


NVD link : CVE-2000-0670

Mitre link : CVE-2000-0670

CVE.ORG link : CVE-2000-0670


JSON object : View

Products Affected

cvsweb_developer

  • cvsweb