CVE Vulnerabilities

CVE-1999-0146

Published: Jul 15, 1997 | Modified: May 03, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.

Affected Software

Name Vendor Start Version End Version
Campas Ncsa * *
Servers Ncsa * *

References