Vulnerabilities > CVE-2000-0690 - Unspecified vulnerability in CGI Script Center Auction Weaver 1.0/1.02

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
cgi-script-center
critical
exploit available

Summary

Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.

Vulnerable Configurations

Part Description Count
Application
Cgi_Script_Center
2

Exploit-Db

descriptionCGI Script Center Auction Weaver 1.0.2 Remote Command Execution Vulnerability. CVE-2000-0690. Remote exploit for cgi platform
idEDB-ID:20194
last seen2016-02-02
modified2000-08-30
published2000-08-30
reporterteleh0r
sourcehttps://www.exploit-db.com/download/20194/
titleCGI Script Center Auction Weaver 1.0.2 - Remote Command Execution Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/23375/auction.weaver.txt
idPACKETSTORM:23375
last seen2016-12-05
published2000-10-19
reportermitre.org
sourcehttps://packetstormsecurity.com/files/23375/auction.weaver.txt.html
titleauction.weaver.txt