PT-1999-1604 · Website Pro+1 · Website Pro+1
Published
1999-02-16
·
Updated
2008-09-10
·
CVE-1999-1180
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
O'Reilly WebSite version 1.1e
Website Pro version 2.0
Description
The issue allows remote attackers to execute arbitrary commands. This can be achieved by using shell metacharacters in an argument to either the
args.cmd or args.bat functions.Recommendations
For O'Reilly WebSite version 1.1e, consider disabling the
args.cmd and args.bat functions until a patch is available.
For Website Pro version 2.0, restrict access to the args.cmd and args.bat functions to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
O'Reilly Website
Website Pro