CVE-2000-0169
published 2000-03-15CVE-2000-0169: Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
26.69%
97.8th percentile
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Application Server 4.0 on Win NT Web Listener /ows-bin privileges management (EDB-19809 / Nessus ID 57619)
vuldb·2026-04-21·CVSS 7.5
CVE-2000-0169 [HIGH] Oracle Application Server 4.0 on Win NT Web Listener /ows-bin privileges management (EDB-19809 / Nessus ID 57619)
A vulnerability was found in Oracle Application Server 4.0 on Win NT. It has been classified as critical. This affects an unknown part of the file /ows-bin of the component Web Listener. This manipulation with the input ?& causes improper privilege management.
This vulnerability is handled as CVE-2000-0169. The attack can be initiated remotely. Additionally, an exploit exists.
Upgrading the affected component is recommended.
GHSA
GHSA-j2cp-x56j-p654: Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'
ghsa_unreviewed·2022-04-30
CVE-2000-0169 [HIGH] GHSA-j2cp-x56j-p654: Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
No detection rules found.
2000-03-15
Published