CVE-2000-0149
Zeus Web Server - Source Code Disclosure via Null Character in URL
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-0149. PoCs published by Vanja Hrustic.
AI-analyzed exploit summary This exploit describes a vulnerability in certain web servers where appending specific URL-encoded characters to a CGI script filename allows remote clients to view the script's source code. The vulnerability is triggered when the CGI module option 'allow CGIs anywhere' is enabled.
Description
Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL.
Exploits (1)
This exploit describes a vulnerability in certain web servers where appending specific URL-encoded characters to a CGI script filename allows remote clients to view the script's source code. The vulnerability is triggered when the CGI module option 'allow CGIs anywhere' is enabled.