Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-1999-0885 | First vendor Publication | 1999-11-03 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 3.6 | Attack Range | Local |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0885 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
14 | Alibaba tst.bat Arbitrary Command Execution Alibaba Web Server contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the tst.bat script not sanitizing arguments supplied to it. With a specially crafted request, an attacker can provide additional commands that will be executed. |
13 | Alibaba alibaba.pl Arbitrary Command Execution Alibaba Web Server contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the alibaba.pl script not sanitizing arguments supplied to it. With a specially crafted request, an attacker can provide additional commands that will be executed. |
11 | Alibaba get32.exe Arbitrary Command Execution Alibaba Web Server contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the get32.exe program not sanitizing user-supplied input. By appending additional commands via a | character, arbitrary commands can be executed under the privileges of the web server. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | tst.bat access RuleID : 1650-community - Revision : 15 - Type : SERVER-WEBAPP |
2014-01-10 | tst.bat access RuleID : 1650 - Revision : 15 - Type : SERVER-WEBAPP |
2014-01-10 | alibaba.pl access RuleID : 1508-community - Revision : 17 - Type : SERVER-WEBAPP |
2014-01-10 | alibaba.pl access RuleID : 1508 - Revision : 17 - Type : SERVER-WEBAPP |
2014-01-10 | alibaba.pl arbitrary command execution attempt RuleID : 1507-community - Revision : 18 - Type : SERVER-WEBAPP |
2014-01-10 | alibaba.pl arbitrary command execution attempt RuleID : 1507 - Revision : 18 - Type : SERVER-WEBAPP |
2014-01-10 | get32.exe access RuleID : 1180-community - Revision : 24 - Type : SERVER-WEBAPP |
2014-01-10 | get32.exe access RuleID : 1180 - Revision : 24 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
1999-11-04 | Name : Arbitrary command may be run on this server. File : alibaba_get32.nasl - Type : ACT_GATHER_INFO |
1999-11-04 | Name : The remote web server is affected by an information disclosure vulnerability. File : alibaba_tst.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:24:53 |
|
2024-11-28 12:03:47 |
|
2023-11-07 21:48:14 |
|
2021-05-04 12:00:57 |
|
2021-04-22 01:01:11 |
|
2020-05-23 00:14:10 |
|
2014-02-17 10:22:40 |
|
2014-01-19 21:20:50 |
|
2013-05-11 11:57:25 |
|