CVE-1999-0753

Mini SQL - Directory Traversal via w3-msql CGI Script

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0753. PoCs published by Gregory Duchemin.

AI-analyzed exploit summary The writeup describes a vulnerability in Mini SQL's w3-msql CGI script that allows unauthorized directory access and password file retrieval due to improper handling of form data as global variables. It outlines two attack approaches: direct access to protected files and retrieval of .htpasswd for offline cracking.

Description

The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Gregory Duchemin · textremotemultiple
https://www.exploit-db.com/exploits/19466

The writeup describes a vulnerability in Mini SQL's w3-msql CGI script that allows unauthorized directory access and password file retrieval due to improper handling of form data as global variables. It outlines two attack approaches: direct access to protected files and retrieval of .htpasswd for offline cracking.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Mini SQL w3-msql CGI script
No auth needed
Prerequisites: Knowledge of target directory structure
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/591

Scores

EPSS 0.0533
EPSS Percentile 91.6%

Details

Status published
Products (2)
hughes/msql 2.0
hughes/msql 2.0.10
Published Aug 17, 1999
Tracked Since Feb 18, 2026