CVE-2000-0690

Auction Weaver <= 1.02 - Remote Command Execution via fromfile Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0690. PoCs published by teleh0r.

AI-analyzed exploit summary This exploit targets a command injection vulnerability in Auction Weaver 1.02 by manipulating the 'fromfile' parameter to execute arbitrary commands. It spawns an xterm from the target to the attacker's machine.

Description

Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by teleh0r · perlremotecgi
https://www.exploit-db.com/exploits/20194

This exploit targets a command injection vulnerability in Auction Weaver 1.02 by manipulating the 'fromfile' parameter to execute arbitrary commands. It spawns an xterm from the target to the attacker's machine.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: CGI Script Center's Auction Weaver 1.02
No auth needed
Prerequisites: Target must be running Auction Weaver 1.02 on a Unix-like system · Attacker must have network access to the target · X11 forwarding must be allowed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-08/0452.html
Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-08/0370.html

Scores

EPSS 0.1051
EPSS Percentile 95.2%

Details

Status published
Products (2)
cgi_script_center/auction_weaver 1.0
cgi_script_center/auction_weaver 1.02
Published Oct 20, 2000
Tracked Since Feb 18, 2026