Vulnerabilities > CVE-1999-0146 - Unspecified vulnerability in Ncsa Campas and Servers

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
ncsa
nessus
exploit available

Summary

The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.

Vulnerable Configurations

Part Description Count
Application
Ncsa
2

Exploit-Db

descriptionNCSA httpd-campas 1.2 sample script Vulnerability. CVE-1999-0146. Remote exploit for cgi platform
idEDB-ID:20423
last seen2016-02-02
modified1997-07-15
published1997-07-15
reporterFrancisco Torres
sourcehttps://www.exploit-db.com/download/20423/
titleNCSA httpd-campas 1.2 sample script Vulnerability

Nessus

NASL familyCGI abuses
NASL idCAMPAS.NASL
descriptionThe remote web server appears to be NCSA httpd. This version of the web server comes with a sample CGI script, campas, that fails to properly sanitize user input. This could allow a remote attacker to execute arbitrary commands with the privileges of the web server.
last seen2020-06-01
modified2020-06-02
plugin id10035
published1999-06-22
reporterThis script is Copyright (C) 1999-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10035
titleNCSA Campas cgi-bin Arbitrary Command Execution