CVE Vulnerabilities

CVE-2000-0639

Published: Jun 11, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.

Affected Software

NameVendorStart VersionEnd Version
Big_brotherSean_macguire1.0 (including)1.0 (including)
Big_brotherSean_macguire1.1 (including)1.1 (including)
Big_brotherSean_macguire1.2 (including)1.2 (including)
Big_brotherSean_macguire1.3 (including)1.3 (including)
Big_brotherSean_macguire1.3b (including)1.3b (including)
Big_brotherSean_macguire1.4 (including)1.4 (including)
Big_brotherSean_macguire1.4g (including)1.4g (including)
Big_brotherSean_macguire1.4h (including)1.4h (including)
Big_brotherSean_macguire1.4h1 (including)1.4h1 (including)
Big_brotherSean_macguire1.09b (including)1.09b (including)
Big_brotherSean_macguire1.09c (including)1.09c (including)
Big_brotherSean_macguire1.09d (including)1.09d (including)

References