Lucene search

K
cveMitreCVE-2001-1130
HistoryJun 25, 2002 - 4:00 a.m.

CVE-2001-1130

2002-06-2504:00:00
mitre
web.nvd.nist.gov
35
suse linux
remote attack
arbitrary commands
cve-2001-1130
vulnerability
sdbsearch.cgi

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.047

Percentile

92.7%

Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a … in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.

Affected configurations

Nvd
Node
susesuse_linuxMatch6.0
OR
susesuse_linuxMatch6.3
OR
susesuse_linuxMatch6.4
OR
susesuse_linuxMatch7.0
OR
susesuse_linuxMatch7.1
OR
susesuse_linuxMatch7.2
VendorProductVersionCPE
susesuse_linux6.0cpe:2.3:o:suse:suse_linux:6.0:*:*:*:*:*:*:*
susesuse_linux6.3cpe:2.3:o:suse:suse_linux:6.3:*:*:*:*:*:*:*
susesuse_linux6.4cpe:2.3:o:suse:suse_linux:6.4:*:*:*:*:*:*:*
susesuse_linux7.0cpe:2.3:o:suse:suse_linux:7.0:*:*:*:*:*:*:*
susesuse_linux7.1cpe:2.3:o:suse:suse_linux:7.1:*:*:*:*:*:*:*
susesuse_linux7.2cpe:2.3:o:suse:suse_linux:7.2:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.047

Percentile

92.7%