CVE-2000-0975

Anaconda Foundation Directory - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0975. PoCs published by pestilence.

AI-analyzed exploit summary The exploit describes a directory traversal vulnerability in Anaconda Foundation Directory via the 'apexec.pl' script. Attackers can access arbitrary files by manipulating the 'template' parameter with '../' sequences and null bytes followed by '.html'.

Description

Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Exploits (1)

exploitdb WRITEUP VERIFIED
by pestilence · textremotecgi
https://www.exploit-db.com/exploits/20611

The exploit describes a directory traversal vulnerability in Anaconda Foundation Directory via the 'apexec.pl' script. Attackers can access arbitrary files by manipulating the 'template' parameter with '../' sequences and null bytes followed by '.html'.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Anaconda Foundation Directory (versions including 1.5 and later)
No auth needed
Prerequisites: Access to the target web server hosting 'apexec.pl'
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/435
Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-10/0210.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5750

Scores

EPSS 0.0358
EPSS Percentile 88.0%

Details

Status published
Products (1)
anaconda_partners/foundation_directory
Published Dec 19, 2000
Tracked Since Feb 18, 2026