CVE-1999-0984 describes a command injection vulnerability in Matt's Whois program, specifically within the whois.cgi script. Remote attackers can execute arbitrary commands by injecting shell metacharacters into the domain entry field. This vulnerability carries a high CVSS score of 7.5, indicating a severe risk with network-based attacks requiring low complexity and leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding this legacy CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:matts_whois:matts_whois:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.