CVE-1999-0146 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 14.9% (pctl 97)
Patch early
A public exploit exists.
Description
The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 14.94% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 1997-07-15 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| ncsa | campas |
| ncsa | servers |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | NCSA httpd-campas 1.2 - sample script | 1997-07-15 |
References
→ the Explorer · watch your stack · NVD