« Volver al listado

CVE-2000-0639

Estado: ModificadaAlta (7.5)—

The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2000-0639",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2000-06-11T04:00:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2000-07/0171.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/1472",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/1494",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/5103",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2000-07/0171.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/1472",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/1494",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/5103",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server."
    }
  ],
  "lastModified": "2026-06-16T21:52:09.987",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B040ABE-485E-4118-989B-6618062A62E7"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2D180EE-6ACC-4F1F-8FEE-3CC790AEC74A"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3435B00B-59AB-4F7F-8936-4DB44581C2E9"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4F30DBF-78E2-4E6C-BCBF-4E43D0207B69"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.3b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "073613CC-638B-46A9-8BBD-A1D313864BD2"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D29324C9-7C4A-4A5A-A595-A0666498AC88"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.4g:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FDEC456-9591-4195-A251-2196F3049A22"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.4h:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7CCF8C5-927E-4D94-9D8D-631134CCF51F"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.4h1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A6B2570-E8A4-41C8-A5AD-D64333A133E6"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.09b:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69480B13-B4AA-4224-8775-507B4971089D"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.09c:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD961EAE-09E4-4574-BDF2-DAA0CB830247"
            },
            {
              "criteria": "cpe:2.3:a:sean_macguire:big_brother:1.09d:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B508CE19-E1B7-4240-A86F-D751F40066F6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}