Vulnerability record · CVE-1999-0067 · published 20 March 1996
CVE-1999-0067: phf CGI program allows remote command execution via shell metacharacters
Apache · Http Server
The phf CGI program, shipped with NCSA HTTPd and Apache HTTP Server, fails to sanitize shell metacharacters in user input, allowing OS command injection. Because the CGI is reachable over the network without authentication, an attacker can execute arbitrary commands on the web server. This is a classic, well-documented remote code execution flaw in a legacy component.
Description
phf CGI program allows remote command execution through shell metacharacters.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete impact, combined with a very high EPSS probability, makes this a critical risk for any system still running the vulnerable component.
What it is
The phf CGI program, shipped with NCSA HTTPd and Apache HTTP Server, fails to sanitize shell metacharacters in user input, allowing OS command injection. Because the CGI is reachable over the network without authentication, an attacker can execute arbitrary commands on the web server. This is a classic, well-documented remote code execution flaw in a legacy component.
Impact
An attacker gains remote command execution with the privileges of the web server process, leading to full compromise of confidentiality, integrity, and availability. This can result in data theft, defacement, or use of the host as a pivot point.
Attack surface
Reachable remotely over HTTP by requesting the phf CGI script; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N. The flaw is triggered by supplying shell metacharacters in request parameters.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS indicates a high probability of exploitation activity (0.86871, 99.7th percentile). No ransomware group associations are documented.
What to do
- Patch or upgrade to a version of Apache HTTP Server or NCSA HTTPd that removes or fixes the phf CGI program.
- If patching is not possible, remove or disable the phf CGI script and any related sample CGI programs.
- Restrict access to CGI directories using web server configuration or network controls.
- Run the web server with least privilege to limit the impact of command execution.
- Monitor for and block requests containing shell metacharacters targeting CGI paths.
Detection
- Inspect web server access logs for requests to /cgi-bin/phf or similar paths containing shell metacharacters (e.g., ;, |, `, $()).
- Monitor process creation on web servers for unexpected child processes spawned by the web server user.
- Use file integrity monitoring to detect changes to CGI scripts or web server binaries.
- Deploy network signatures to alert on command injection patterns in HTTP requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.cert.org/advisories/CA-1996-06.html | Third Party AdvisoryUS Government Resource |
| http://www.osvdb.org/136 | Broken Link |
| http://www.securityfocus.com/bid/629 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.cert.org/advisories/CA-1996-06.html | Third Party AdvisoryUS Government Resource |
| http://www.osvdb.org/136 | Broken Link |
| http://www.securityfocus.com/bid/629 | Broken LinkThird Party AdvisoryVDB Entry |
Track CVE-1999-0067 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-1999-0067), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.