Junglewise Threat Intelligence

CVE-1999-0509: Generic Web Server remote command execution via interpreters in cgi-bin

CVE-1999-0509 · Severity: critical · CVSS 10 · Published 1996-05-29

Vendors: Generic.

Executive brief

A configuration error on certain web servers allows attackers to run commands directly on the hosting system. This occurs when powerful system tools, like command shells or script interpreters, are mistakenly placed in a publicly accessible folder intended for web scripts. An attacker can exploit this to take full control of the server, steal sensitive data, or disrupt business operations.

Technical details

This vulnerability is a classic configuration-based remote code execution (RCE) flaw. It occurs when administrative errors lead to the placement of binary interpreters (e.g., /bin/sh, /usr/bin/perl) within the web server's CGI executable directory (typically /cgi-bin/). Because the web server is designed to execute files in this directory upon request, a remote, unauthenticated attacker can invoke these interpreters via a crafted URL. By passing command-line arguments through the URL or request body, the attacker can execute arbitrary system commands on the host operating system. This typically results in full system compromise under the context of the web server user.

Affected products

  • Generic CGI-enabled Web Servers

Timeline

  • 1996-05-29: advisory: Initial publication in the NVD database.

References