Exploitation Summary
EIP tracks 2 public exploits for CVE-1999-0066. PoCs published by Paul Phillips, HORKimhab.
AI-analyzed exploit summary This exploit leverages a command injection vulnerability in AnyForm CGI by embedding shell commands in the 'AnyFormTo' parameter, which is passed unsanitized to a system call. The semicolons in the input are interpreted as command delimiters, allowing arbitrary command execution.
Description
AnyForm CGI remote execution.
Exploits (2)
This exploit leverages a command injection vulnerability in AnyForm CGI by embedding shell commands in the 'AnyFormTo' parameter, which is passed unsanitized to a system call. The semicolons in the input are interpreted as command delimiters, allowing arbitrary command execution.
The repository contains a placeholder markdown file for CVE-1999-0066, a remote command execution vulnerability in AnyForm CGI. The file lacks any technical details, exploit code, or proof-of-concept implementation.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H