Vulnerability Description
The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Solaris Answerbook2 | 1.3 |
References
- http://archives.neohapsis.com/archives/sun/2000-q3/0001.htmlPatchVendor Advisory
- http://seclists.org/bugtraq/2000/Aug/0105.html
- http://www.iss.net/security_center/static/5058.php
- http://www.s21sec.com/en/avisos/s21sec-004-en.txt
- http://www.securityfocus.com/bid/1556ExploitPatchVendor Advisory
- http://archives.neohapsis.com/archives/sun/2000-q3/0001.htmlPatchVendor Advisory
- http://seclists.org/bugtraq/2000/Aug/0105.html
- http://www.iss.net/security_center/static/5058.php
- http://www.s21sec.com/en/avisos/s21sec-004-en.txt
- http://www.securityfocus.com/bid/1556ExploitPatchVendor Advisory
FAQ
What is CVE-2000-0697?
CVE-2000-0697 is a vulnerability with a CVSS score of 10.0 (HIGH). The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.
How severe is CVE-2000-0697?
CVE-2000-0697 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0697?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Solaris Answerbook2.