peter bassill · operator
$ cve CVE-1999-0146 JSON

CVE-1999-0146 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 14.9% (pctl 97)

Patch early

A public exploit exists.

Description

The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS14.94% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published1997-07-15
Last modified2026-06-16

Affected (2)

VendorProduct
ncsacampas
ncsaservers

Public exploits

SourceTitleDate
exploit-dbNCSA httpd-campas 1.2 - sample script1997-07-15

References

→ the Explorer  ·  watch your stack  ·  NVD