Korean
<< Back
VID 21610
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The IkonBoard program is vulnerable to a directory traversal vulnerability in the help.cgi file. IkonBoard is a freely available Web Bulletin Board System written in Perl. IkonBoard version 2.1.7b and earlier versions could allow a remote attacker to traverse directories on the system, caused by improper filtering of user-supplied input passed to the 'helpon' parameter of the 'help.cgi' file. A remote attacker could send a specially-crafted URL request including dot-dot-slash (../) character sequences to the 'helpon' parameter of the 'help.cgi' file and read arbitrary files outside of the document root.

* References:
http://archives.neohapsis.com/archives/bugtraq/2001-03/0124.html

* Platforms Affected:
Jarvis Entertainment Group, Inc., IkonBoard version 2.1.7b and earlier versions
Any operating system Any version
Recommendation Upgrade to the latest version of IkonBoard (2.1.8 or later), available from the IkonBoard Web site at http://www.ikonboard.com/
Related URL CVE-2001-0360 (CVE)
Related URL 2471 (SecurityFocus)
Related URL 6216 (ISS)