Exploitation Summary
EIP tracks 1 public exploit for CVE-2000-0010. PoCs published by loophole.
AI-analyzed exploit summary This exploit targets a command injection vulnerability in WebWho+ v1.1 by sending a maliciously crafted POST request to the 'type' parameter, allowing arbitrary command execution with the web server's privileges. The script uses Perl and IO::Socket to interact with the vulnerable CGI script.
Description
WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.
Exploits (1)
This exploit targets a command injection vulnerability in WebWho+ v1.1 by sending a maliciously crafted POST request to the 'type' parameter, allowing arbitrary command execution with the web server's privileges. The script uses Perl and IO::Socket to interact with the vulnerable CGI script.