PT-2006-6913 · Vikingboard · Vikingboard
Benjamin Moss
+1
·
Published
2006-12-04
·
Updated
2018-10-17
·
CVE-2006-6284
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vikingboard version 0.1.2
Description
The issue allows remote authenticated administrators to include arbitrary files via a .. (dot dot) sequence in the
act parameter of the admin.php file.Recommendations
For Vikingboard version 0.1.2, consider restricting access to the admin.php file to prevent exploitation, and avoid using the
act parameter with unvalidated input until a fix is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vikingboard