Junglewise Threat Intelligence

CVE-1999-0177: O'Reilly WebSite arbitrary command execution in uploader program

CVE-1999-0177 · Severity: high · CVSS 7.5 · Published 1997-09-01

Executive brief

The WebSite web server contains a flaw in its file upload utility that allows remote attackers to run unauthorized programs on the server. This could lead to a complete takeover of the web server, allowing attackers to steal data, modify website content, or disrupt services. Organizations using this legacy web server software are at high risk of remote compromise.

Technical details

A remote code execution vulnerability exists in the 'uploader' CGI program bundled with the WebSite web server. The vulnerability allows an unauthenticated remote attacker to bypass intended restrictions and execute arbitrary commands or programs on the underlying host. This is likely due to insufficient validation of input parameters passed to the uploader script, a common issue in early CGI implementations. Successful exploitation grants the attacker the privileges of the web server process, potentially leading to full system compromise. Users should disable the uploader program or migrate to a supported web server platform.

Affected products

  • O'Reilly WebSite web server

Timeline

  • 1997-09-01: disclosed

References