PT-2001-1311 · Ikonboard · Ikonboard
Publicado
2001-02-02
·
Atualizado
2017-12-19
·
CVE-2001-0076
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Ikonboard versions 2.1.7b and earlier
Description:
The issue allows remote attackers to execute arbitrary commands via the
SEND MAIL parameter in the "register.cgi" endpoint. This parameter overwrites an internal program variable that references a program to be executed.Recommendations:
For Ikonboard versions 2.1.7b and earlier, consider restricting access to the "register.cgi" endpoint until a fix is available, and avoid using the
SEND MAIL parameter to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ikonboard