VulnerabilityModified
CVE-2000-0941
Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.
HIGH 10.0EPSS 13.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 13.46% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- kootenay web inc/kootenay web inc whois
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0420.htmlPatch, Vendor Advisory
- http://www.kootenayweb.bc.ca/scripts/whois.txt
- http://www.securityfocus.com/bid/1883Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5438
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0420.htmlPatch, Vendor Advisory
- http://www.kootenayweb.bc.ca/scripts/whois.txt
- http://www.securityfocus.com/bid/1883Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5438
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.