CVE
- Id
- 2266
- CVE No.
- CVE-2000-0690
- Status
- Candidate
- Description
- Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.
- Phase
- Proposed (20000921)
- Votes
- ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall
- Comments
- Levy> Reference: BID 1645 | Christey> BID:1645 | URL:http://www.securityfocus.com/bid/1645 | Frech> XF:auction-weaver-execute-commands(6175)