← back
CVE-1999-0146

CVE-1999-0146

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 15%
from disclosure to weapon0 days
Published on NVDSep 29
1st PoCJul 15
exploitation probability
15%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.