CVE-1999-1333
Published Dec 31, 1999
Last updated 8 years ago
Overview
- Description
- automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:redhat:linux:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "040166C7-CB3A-485E-9337-CB679B779BF8", "versionEndIncluding": "5.0" } ], "operator": "OR" } ] } ]