PT-1997-1092 · Webgais · Webgais

Published

1997-07-08

·

Updated

2008-09-09

·

CVE-1999-0196

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Webgais version 1.0
Description The issue allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter, specifically the $VAR receiver variable, in the websendmail component.
Recommendations For Webgais version 1.0, consider restricting access to the websendmail component or the $VAR receiver variable to minimize the risk of exploitation until a patch is available. Avoid using the receiver parameter in the affected component until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-0196

Affected Products

Webgais