Common Gateway Interface Interface
(CGI) Access| Exploit | CVE | Characteristic | Reference | |
| webdist | 1999-0039 | Execute commands on IRIX Web Server | http://www.securityfocus.com/bid/374 | |
| phf | 1999-0067 | Execute commands on Web Server | http://www.securityfocus.com/bid/629 | |
| campas | 1999-0146 | Execute commands on Web Server | http://xforce.iss.net/static/298.php | |
| handler | 1999-0148 | Execute commands on IRIX Web Server | http://www.securityfocus.com/bid/380 | |
| htmlscript | 1999-0264 | Access files on Web Server | http://xforce.iss.net/static/1466.php | |
| php | 1999-0058 | View files on Web Server | http://www.securityfocus.com/bid/911 | |
| count | 1999-0021 | Execute commands on Web Server | http://www.securityfocus.com/bid128 | |
| jj | 1999-0260 | View files on Web Server | http://xforce.iss.net/static/1808.php | |
| pfdispaly | 1999-0270 | Access files on Web Server | http://www.securityfocus.com/bid/64 | |
| faxsurvey | 1999-0262 | Execute commands on Web Server | http://xforce.iss.net/static/1532.php | |
| info2www | 1999-0266 | Execute commands on Web Server | http://xforce.iss.net/static/1732.php | |
| glimpse | 1999-0148 | Access files on IRIX Web Server | http://xforce.iss.net/static/340.php | |
| webgais | 1999-0176 | Execute commands on Web Server | http://xforce.iss.net/static/296.php | |
| websendmail | 1999-0196 | Execute commands on Web Server | http://xforce.iss.net/static/296.php | |
| perl | Execute commands on Web Server | Remove from Web directories | ||
| view_source | 1999-0174 | View files on Web Server | http://www.securityfocus.com/bid/303 | |
| uploader | 1999-0177 | Load/execute files on Webite Server | http://xforce.iss.net/static/294.php | |
| args.cmd | Execute commands on Website Server | Delete file | ||
| product.asp | 2000-0161 | Execute SQL commands on MS Server | http://xforce.iss.net/static/3997.php | |
| win-c-sample | 1999-0178 | Execute commands on Web Server | http://www.securityfocus.com/bid/994 | |
| htsearch | 2000-0208 | View files on Web Server | http://www.securityfocus.com/bid/1026 | |
| infosrch | 2000-0207 | View files on IRIX Web Server | http://www.securityfocus.com/bid/1031 | |
| test-cgi | 1999-0070 | Web Server provides system information | http://xforce.iss.net/static/149.php | |
| nph-test | 1999-0045 | Web Server provides system information | http://xforce.iss.net/static/289.php | |
| wrap | 1999-0149 | IRIX Server provides system information | http://xforce.iss.net/static/290.php | |
| bash | Direct shell access from Web Server | Remove from Web directories | ||
| csh | Direct shell access from Web Server | Remove from Web directories | ||
| ksh | Direct shell access from Web Server | Remove from Web directories | ||
| tcsh | Direct shell access from Web Server | Remove from Web directories | ||
| zsh | Direct shell access from Web Server | Remove from Web directories | ||
| coldfusion | 2000-0189 | Access files on Web Server | http://www.securityfocus.com/bid/1021 | |
| frontpage | Access to files on Web Server | http://xforce.iss.net/static/3682.php | ||
| code | Read files on MS Web Server | http://xforce.iss.net/static/2383.php | ||
| codebrws | Read files on MS Web Server | http://xforce.iss.net/static/2383.php | ||
| showcode | Read files on MS Web Server | http://xforce.iss.net/static/2383.php | ||
| pirahna | Execute commands on Linux Server | http://xforce.iss.net/static/4307.php | ||
| visdev | 2000-0260 | Execute commands on IIS Server | http://xforce.iss.net/static/4333.php | |
| rds | Execute commands on IIS Server | http://xforce.iss.net/static/1212.php | ||
| ezshopper | Execute commands on Web Server | http://xforce.iss.net/static/4044.php | ||
| mylog | 1999-0068 | View files on Web Server | http://xforce.iss.net/static/1468.php | |
| mlog | 1999-0346 | View files on Web Server | http://xforce.iss.net/static/1505.php | |
| jetadmin | View files on Web Server | http://xforce.iss.net/static/4525.php | ||
| big brother | View files on Web Server | http://xforce.iss.net/static/4879.php | ||
| source.asp | Write files on Apache Servers | http://xforce.iss.net/static/4931.php | ||
| pollit cgi | View files on Web Server | http://xforce.iss.net/static/4878.php | ||
| answerbook2 | Execute commands on wdhttpd Server | http://www.securityfocus.com/bid/253 | ||
| photoalbum | Execute commands on Web Server | http://www.securityfocus.com/bid/1650 | ||
| machineinfo | View IRIX info on Web Server | http://xforce.iss.net/static/1730.php | ||
| PUT Request | Write files on Web Server | Check Permissions for / and /cgi-bin | ||
| PHP | Execute commands on Web Server | http://www.securityfocus.com/bid/1786 | ||
| Web Shopper | Read files on Web Server | http://www.securityfocus.com/bid/1776 | ||
| Shopping Cart | Read files on Web Server | http://www.securityfocus.com/bid/1777 | ||
| Netauth CGI | dot-dot directory traversal | http://www.securityfocus.com/bid/1587 | ||
| calendar.pl | Execute files on server | http://www.securityfocus.com/bid/1215 | ||
| WebLogic | CVE-2000-0682 CVE-2000-0683 CVE-2000-0684 CVE-2000-0685 | Execute files on server Read files on server | http://www.securityfocus.com/bid/2138 http://www.securityfocus.com/bid/1570 http://www.securityfocus.com/bid/1525 http://www.securityfocus.com/bid/1517 | |
| (command execution) | Execute commands on IIS server |
http://www.securityfocus.com/bid/1806 www.nsfocus.com/english/homepage/sa01-02.htm | ||
| Bugzilla | Execute commands on Bugzilla server | http://www.securityfocus.com/bid/2671 |
Resolution of the exploit(s) is provided in the Table Reference