The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 1997-07-14 21:00
Updated : 2018-05-02 18:29
NVD link : CVE-1999-0146
Mitre link : CVE-1999-0146
JSON object : View
CWE
Products Affected
ncsa
- servers
- campas