Junglewise Threat Intelligence

CVE-1999-0196: Webgais Webgais arbitrary code execution in websendmail

CVE-1999-0196 · Severity: medium · CVSS 5 · Published 1997-07-08

Executive brief

Webgais is a legacy web-based gateway and search interface. A security flaw in its 'websendmail' component allows remote attackers to bypass security restrictions to view private files on the server or execute unauthorized commands. This could lead to the theft of sensitive data or a complete takeover of the web server.

Technical details

The websendmail CGI script in Webgais 1.0 contains an input validation vulnerability. By manipulating the '$VAR_receiver' parameter, a remote, unauthenticated attacker can perform command injection or directory traversal. This allows for the reading of arbitrary files on the host system and the execution of arbitrary system commands with the privileges of the web server process. The vulnerability is reachable over the network without prior authentication.

Affected products

  • Webgais Webgais 1.0

Timeline

  • 1997-07-08: disclosed

References

Related threats