PT-2000-1299 · Ultraboard · Ultraboard

Published

2000-05-03

·

Updated

2008-09-10

·

CVE-2000-0332

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions UltraBoard version 1.6
Description The issue allows remote attackers to read arbitrary files by providing a pathname string that includes a dot dot (..) and ends with a null byte. This is related to the UltraBoard.pl or UltraBoard.cgi CGI scripts.
Recommendations For UltraBoard version 1.6, consider restricting access to the UltraBoard.pl and UltraBoard.cgi scripts until a fix is available, or apply a configuration change to prevent the use of dot dot (..) and null byte in pathname strings.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0332

Affected Products

Ultraboard