CVE-1999-0113

Some implementations of rlogin - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-1999-0113. PoCs published by anonymous, HORKimhab.

AI-analyzed exploit summary This exploit leverages a vulnerability in the rlogin service where improper parsing of arguments allows an attacker to bypass authentication and gain root access. The command 'rlogin -froot targethost.com' exploits this flaw by directly specifying the root username.

Description

Some implementations of rlogin allow root access if given a -froot parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by anonymous · textremoteaix
https://www.exploit-db.com/exploits/19348

This exploit leverages a vulnerability in the rlogin service where improper parsing of arguments allows an attacker to bypass authentication and gain root access. The command 'rlogin -froot targethost.com' exploits this flaw by directly specifying the root username.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: rlogin (various versions, particularly older implementations)
No auth needed
Prerequisites: Network access to the target host · rlogin service enabled on the target
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
github STUB
by HORKimhab · shellpoc
https://github.com/HORKimhab/poc-cve-collection/tree/main/1999/0xxx/CVE-1999-0113.md

The repository contains a placeholder markdown file for CVE-1999-0113, describing a historical rlogin vulnerability that allowed root access via the -froot parameter. However, no functional exploit code, technical analysis, or proof-of-concept is provided.

Classification
Stub 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: rlogin (specific implementations vulnerable to -froot parameter)
No auth needed
Prerequisites: Access to a vulnerable rlogin service · Network connectivity to the target
mistral-large-3 · analyzed Jul 15, 2026 Full analysis →

References (1)

Core 1
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/458

Scores

EPSS 0.1717
EPSS Percentile 96.8%

Details

CWE
CWE-88
Status published
Products (4)
ibm/aix 3.1
ibm/aix 3.2
ibm/aix 3.2.4
ibm/aix 3.2.5
Published May 23, 1994
Tracked Since Feb 18, 2026