CVE-2000-0039

AltaVista Search Intranet - Directory Traversal via Query.cgi

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0039. PoCs published by Rudi Carell.

AI-analyzed exploit summary This exploit leverages directory traversal in AltaVista Search engine's webserver on port 9000 to access sensitive files like logs/mgtstate (containing base64-encoded admin credentials) or /etc/passwd. The PoC includes a Perl script to decode the credentials and demonstrates both single and hex-encoded '../' traversal techniques.

Description

AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Rudi Carell · textremoteunix
https://www.exploit-db.com/exploits/19694

This exploit leverages directory traversal in AltaVista Search engine's webserver on port 9000 to access sensitive files like logs/mgtstate (containing base64-encoded admin credentials) or /etc/passwd. The PoC includes a Perl script to decode the credentials and demonstrates both single and hex-encoded '../' traversal techniques.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: AltaVista Search engine
No auth needed
Prerequisites: Network access to port 9000 on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/896

Scores

EPSS 0.0592
EPSS Percentile 92.3%

Details

Status published
Products (2)
altavista/search_intranet 2.0b
altavista/search_intranet 2.3a
Published Dec 29, 1999
Tracked Since Feb 18, 2026