PT-1999-1604 · Website Pro+1 · Website Pro+1

Published

1999-02-16

·

Updated

2008-09-10

·

CVE-1999-1180

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions O'Reilly WebSite version 1.1e Website Pro version 2.0
Description The issue allows remote attackers to execute arbitrary commands. This can be achieved by using shell metacharacters in an argument to either the args.cmd or args.bat functions.
Recommendations For O'Reilly WebSite version 1.1e, consider disabling the args.cmd and args.bat functions until a patch is available. For Website Pro version 2.0, restrict access to the args.cmd and args.bat functions to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1180

Affected Products

O'Reilly Website
Website Pro