CVE-2000-0149

Zeus Web Server - Source Code Disclosure via Null Character in URL

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0149. PoCs published by Vanja Hrustic.

AI-analyzed exploit summary This exploit describes a vulnerability in certain web servers where appending specific URL-encoded characters to a CGI script filename allows remote clients to view the script's source code. The vulnerability is triggered when the CGI module option 'allow CGIs anywhere' is enabled.

Description

Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Vanja Hrustic · textremotecgi
https://www.exploit-db.com/exploits/19747

This exploit describes a vulnerability in certain web servers where appending specific URL-encoded characters to a CGI script filename allows remote clients to view the script's source code. The vulnerability is triggered when the CGI module option 'allow CGIs anywhere' is enabled.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Web servers with CGI module (specific versions not specified)
No auth needed
Prerequisites: CGI module option 'allow CGIs anywhere' enabled · Target script not located in an executable directory
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-02/0057.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/3982
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/977
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/254

Scores

EPSS 0.0738
EPSS Percentile 93.8%

Details

Status published
Products (15)
zeus_technologies/zeus_web_server 3.1.1
zeus_technologies/zeus_web_server 3.1.2
zeus_technologies/zeus_web_server 3.1.3
zeus_technologies/zeus_web_server 3.1.4
zeus_technologies/zeus_web_server 3.1.5
zeus_technologies/zeus_web_server 3.1.6
zeus_technologies/zeus_web_server 3.1.7
zeus_technologies/zeus_web_server 3.1.8
zeus_technologies/zeus_web_server 3.1.9
zeus_technologies/zeus_web_server 3.3
... and 5 more
Published Feb 08, 2000
Tracked Since Feb 18, 2026