Korean
<< Back
VID 210117
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The ZeroBoard software has a file disclosure vulnerability. ZeroBoard is a freely available, open source PHP-based bulletin board software, and widely used in Korea. Zeroboard versions 4.1pl8 is vulnerable to allows remote control of the system, caused by write_ok.php file.

* References:
http://www.webmini.net/zeroboard/17463
http://www.mt.co.kr/view/mtview.php?type=1&no=20060613

* Platforms Affected:
Zeroboard versions 4.1pl8 and earlier
Any operating system Any version
Recommendation Apply the appropriate patch for this vulnerability, as listed in Zeroboard4 site at http://www.webmini.net/zeroboard/17463
http://www.mt.co.kr/view/mtview.php?type=1&no=20060613
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)