CVE-2000-1014
Executive Summary
CVE-2000-1014 exposes a format string flaw in the search97.cgi CGI script of the SCO Help HTTP Server on Unixware 7. By injecting format specifiers into the queryText parameter, remote attackers can execute arbitrary commands, enabling full remote code execution. The vulnerability is not currently listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2000-12-11T05:00:00.000 - Last Modified: 2026-09-23T13:10:00.153
Original Description: Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.
"When fate hands us a lemon, lets try to make lemonade."
— Dale Carnegie
Source: NVD