CVE
- Id
- 865
- CVE No.
- CVE-1999-0885
- Status
- Candidate
- Description
- Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.
- Phase
- Modified (20000313-01)
- Votes
- ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(5) Armstrong, Blake, Christey, Cole, LeBlanc
- Comments
- Christey> This candidate is unconfirmed by the vendor. | Blake> Same as CVE-1999-0776. | Frech> XF:alibaba-url-file-manipulation | Christey> CD:SF-LOC and CD:SF-EXEC may say to merge this candidate with | the problems described in: | BUGTRAQ:20000718 Multiple bugs in Alibaba 2.0 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html | | If so, then ADDREF BID:1485 as well. | Christey> Include the names of the affected CGI"s, including tst.bat, | get32.exe, alibaba.pl, etc.