PT-2000-1299 · Ultraboard · Ultraboard
Published
2000-05-03
·
Updated
2008-09-10
·
CVE-2000-0332
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
UltraBoard version 1.6
Description
The issue allows remote attackers to read arbitrary files by providing a pathname string that includes a dot dot (..) and ends with a null byte. This is related to the UltraBoard.pl or UltraBoard.cgi CGI scripts.
Recommendations
For UltraBoard version 1.6, consider restricting access to the UltraBoard.pl and UltraBoard.cgi scripts until a fix is available, or apply a configuration change to prevent the use of dot dot (..) and null byte in pathname strings.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ultraboard