CVE-2000-0128 describes a critical command injection vulnerability in Daniel Beckham's The Finger Server version 0.82. Remote attackers can execute arbitrary commands by injecting shell metacharacters into requests. This vulnerability carries a maximum CVSS score of 10.0, indicating a severe risk with complete compromise of confidentiality, integrity, and availability, requiring no authentication or complex attack vectors. While not listed on the KEV catalog or having significant community discussion, an exploit demonstrating pipe injection is available on ExploitDB, suggesting potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.80_betaCPE matchmatch criteria | cpe:2.3:a:daniel_beckham:the_finger_server:0.80_beta:*:*:*:*:*:*:* | ||
0.81_betaCPE matchmatch criteria | cpe:2.3:a:daniel_beckham:the_finger_server:0.81_beta:*:*:*:*:*:*:* | ||
0.82_betaCPE matchmatch criteria | cpe:2.3:a:daniel_beckham:the_finger_server:0.82_beta:*:*:*:*:*:*:* | ||
0.83_betaCPE matchmatch criteria | cpe:2.3:a:daniel_beckham:the_finger_server:0.83_beta:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.