CVE-1999-0262

faxsurvey - Remote Command Execution via Shell Metacharacters in Query String

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0262. PoCs published by Tom.

AI-analyzed exploit summary This exploit leverages an insecure script (faxsurvey) in Hylafax to execute arbitrary commands via a crafted HTTP request. The vulnerability allows remote command execution with the privileges of the web server process.

Description

Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tom · textremoteunix
https://www.exploit-db.com/exploits/20462

This exploit leverages an insecure script (faxsurvey) in Hylafax to execute arbitrary commands via a crafted HTTP request. The vulnerability allows remote command execution with the privileges of the web server process.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Hylafax (unpatched versions)
No auth needed
Prerequisites: Hylafax installed with the vulnerable faxsurvey script accessible via CGI
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/1532
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2056

Scores

EPSS 0.0907
EPSS Percentile 94.6%

Details

Status published
Products (1)
renaud_deraison/faxsurvey
Published Aug 04, 1998
Tracked Since Feb 18, 2026