CVE-2000-0690
Auction Weaver <= 1.02 - Remote Command Execution via fromfile Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-0690. PoCs published by teleh0r.
AI-analyzed exploit summary This exploit targets a command injection vulnerability in Auction Weaver 1.02 by manipulating the 'fromfile' parameter to execute arbitrary commands. It spawns an xterm from the target to the attacker's machine.
Description
Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by teleh0r · perlremotecgi
https://www.exploit-db.com/exploits/20194
This exploit targets a command injection vulnerability in Auction Weaver 1.02 by manipulating the 'fromfile' parameter to execute arbitrary commands. It spawns an xterm from the target to the attacker's machine.
Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
CGI Script Center's Auction Weaver 1.02
No auth needed
Prerequisites:
Target must be running Auction Weaver 1.02 on a Unix-like system · Attacker must have network access to the target · X11 forwarding must be allowed
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Exploit, Vendor Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-08/0452.html
Vendor Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-08/0370.html
Scores
EPSS
0.1051
EPSS Percentile
95.2%
Details
Status
published
Products (2)
cgi_script_center/auction_weaver
1.0
cgi_script_center/auction_weaver
1.02
Published
Oct 20, 2000
Tracked Since
Feb 18, 2026