CVE-2000-0828 describes a critical buffer overflow vulnerability in ddicgi.exe within Mobius DocumentDirect for the Internet version 1.2. This flaw allows unauthenticated remote attackers to execute arbitrary commands on the affected system by sending a specially crafted, excessively long User-Agent parameter. The vulnerability carries a CVSS score of 10.0 (HIGH), indicating maximum severity due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score of 96/100 further emphasizes its critical nature. While there is no evidence of active exploitation in the wild or KEV listing, a public exploit (EDB-20211) exists on ExploitDB, confirming its exploitability. Despite its age and severity, there is no recorded community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2CPE matchmatch criteria | cpe:2.3:a:mobius:documentdirect_for_the_internet:1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.