Sir · Sir Gnuboard · CVE-2009-0290
**Name of the Vulnerable Software and Affected Versions**
SIR GNUBoard version 4.31.03
**Description**
A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files by using a .. (dot dot) in the `g4 path` parameter. In certain environments, this could potentially be used for remote code execution via a data: URI or a UNC share pathname.
**Recommendations**
For SIR GNUBoard version 4.31.03, consider restricting access to the `g4 path` parameter to prevent directory traversal attacks until a patch is available. As a temporary workaround, avoid using the `g4 path` parameter with untrusted input.