The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.
References
Link | Resource |
---|---|
http://www.securityfocus.com/templates/archive.pike?list=1&msg=38B3E60A.6A84FEC3@cybcom.net | Exploit Vendor Advisory |
http://www.sambar.com/session/highlight?url=/syshelp/history.htm&words=security+&color=red | Vendor Advisory |
http://www.securityfocus.com/bid/1002 | Patch Vendor Advisory |
Configurations
Information
Published : 2000-02-22 21:00
Updated : 2008-09-10 12:03
NVD link : CVE-2000-0213
Mitre link : CVE-2000-0213
JSON object : View
CWE
Products Affected
sambar
- sambar_server