Vulnerabilities > CVE-1999-0146 - Unspecified vulnerability in Ncsa Campas and Servers

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ncsa
nessus
exploit available

Summary

The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.

Vulnerable Configurations

Part Description Count
Application
Ncsa
2

Exploit-Db

descriptionNCSA httpd-campas 1.2 sample script Vulnerability. CVE-1999-0146. Remote exploit for cgi platform
idEDB-ID:20423
last seen2016-02-02
modified1997-07-15
published1997-07-15
reporterFrancisco Torres
sourcehttps://www.exploit-db.com/download/20423/
titleNCSA httpd-campas 1.2 sample script Vulnerability

Nessus

NASL familyCGI abuses
NASL idCAMPAS.NASL
descriptionThe remote web server appears to be NCSA httpd. This version of the web server comes with a sample CGI script, campas, that fails to properly sanitize user input. This could allow a remote attacker to execute arbitrary commands with the privileges of the web server.
last seen2020-06-01
modified2020-06-02
plugin id10035
published1999-06-22
reporterThis script is Copyright (C) 1999-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10035
titleNCSA Campas cgi-bin Arbitrary Command Execution