CVE-2000-0639 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 9.5% (pctl 95)
Patch early
A public exploit exists.
Description
The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 9.49% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2000-06-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sean macguire | big brother |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sean MacGuire Big Brother 1.0/1.3/1.4 - CGI File Creation | 2001-06-11 |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0171.html
- http://www.osvdb.org/1472
- http://www.securityfocus.com/bid/1494
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5103
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0171.html
- http://www.osvdb.org/1472
- http://www.securityfocus.com/bid/1494
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5103
→ the Explorer · watch your stack · NVD