Vulnerabilities > CVE-1999-0021 - Unspecified vulnerability in Muhammad A. Muquit Wwwcount 2.3
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Muhammad A. Muquit wwwcount 2.3 Count.cgi Buffer Overflow Vulnerability. CVE-1999-0021. Remote exploit for linux platform |
id | EDB-ID:19105 |
last seen | 2016-02-02 |
modified | 1997-10-16 |
published | 1997-10-16 |
reporter | Razvan Dragomirescu |
source | https://www.exploit-db.com/download/19105/ |
title | Muhammad A. Muquit wwwcount 2.3 Count.cgi Buffer Overflow Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | COUNT_CGI.NASL |
description | According to its version number, the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10049 |
published | 1999-06-22 |
reporter | This script is Copyright (C) 1999-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10049 |
title | wwwcount Count.cgi Remote Overflow |
code |
|
Seebug
bulletinFamily | exploit |
description | BugCVE: CVE-1999-0021 BUGTRAQ: 128 Count.cgi (wwwcount)是一个非常流行的Web站点跟踪统计CGI程序。一般它作为Web页面点击数统计。1997年10月,这个程序被发现了两个远程漏洞。第一个漏洞比较轻微,它能允许远程用户浏览到受限制的.GIF文件,可能泄漏.GIF文件里潜在的敏感数据。 第二个漏洞比较严重,count.cgi程序在处理QUERY_STRING环境变量的时候存在缓冲区溢出漏洞。远程攻击者可以发送一个超长的请求给程序就能进行溢出攻击,以Web用户的权限在系统执行任意命令。 2.3 Muhammad A. Muquit ------------------ 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载wwwcount 2.4以上版本: <a href=http://www.fccc.edu/users/muquit/Count.html target=_blank>http://www.fccc.edu/users/muquit/Count.html</a> |
id | SSV:4298 |
last seen | 2017-11-19 |
modified | 2008-10-25 |
published | 2008-10-25 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-4298 |
title | Count.cgi(wwwcount)远程缓冲区溢出漏洞 |