CVE-2000-0941
high · 10Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.
10
CVSS
13.5%
EPSS (exploit prob.)
96th
EPSS percentile
2000-12-19
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| kootenay_web_inc | kootenay_web_inc_whois | 1.0 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0420.html
- http://www.kootenayweb.bc.ca/scripts/whois.txt
- http://www.securityfocus.com/bid/1883
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5438
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0420.html
- http://www.kootenayweb.bc.ca/scripts/whois.txt
- http://www.securityfocus.com/bid/1883
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5438
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2000-0941