CVE-1999-0262
faxsurvey - Remote Command Execution via Shell Metacharacters in Query String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-1999-0262. PoCs published by Tom.
AI-analyzed exploit summary This exploit leverages an insecure script (faxsurvey) in Hylafax to execute arbitrary commands via a crafted HTTP request. The vulnerability allows remote command execution with the privileges of the web server process.
Description
Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Tom · textremoteunix
https://www.exploit-db.com/exploits/20462
This exploit leverages an insecure script (faxsurvey) in Hylafax to execute arbitrary commands via a crafted HTTP request. The vulnerability allows remote command execution with the privileges of the web server process.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
Hylafax (unpatched versions)
No auth needed
Prerequisites:
Hylafax installed with the vulnerable faxsurvey script accessible via CGI
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/1532
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/2056
Scores
EPSS
0.0907
EPSS Percentile
94.6%
Details
Status
published
Products (1)
renaud_deraison/faxsurvey
Published
Aug 04, 1998
Tracked Since
Feb 18, 2026