CVE-1999-0935

classifieds.cgi Hidden Variable - Command Injection

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0935. PoCs published by anonymous.

AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in Classifieds.cgi, a Perl script used for classified ads. By manipulating the 'mailprog' hidden form field, an attacker can execute arbitrary commands on the server with the privileges of the web server.

Description

classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · htmlremotecgi
https://www.exploit-db.com/exploits/20442

This exploit demonstrates a command injection vulnerability in Classifieds.cgi, a Perl script used for classified ads. By manipulating the 'mailprog' hidden form field, an attacker can execute arbitrary commands on the server with the privileges of the web server.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Classifieds.cgi (part of the classifieds package by Greg Matthews)
No auth needed
Prerequisites: Access to the vulnerable web application · Ability to submit a crafted HTML form to the server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0935

Scores

EPSS 0.0981
EPSS Percentile 94.9%

Details

Status published
Published Dec 15, 1999
Tracked Since Feb 18, 2026