| VID |
21610 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The IkonBoard program is vulnerable to a directory traversal vulnerability in the help.cgi file. IkonBoard is a freely available Web Bulletin Board System written in Perl. IkonBoard version 2.1.7b and earlier versions could allow a remote attacker to traverse directories on the system, caused by improper filtering of user-supplied input passed to the 'helpon' parameter of the 'help.cgi' file. A remote attacker could send a specially-crafted URL request including dot-dot-slash (../) character sequences to the 'helpon' parameter of the 'help.cgi' file and read arbitrary files outside of the document root.
* References: http://archives.neohapsis.com/archives/bugtraq/2001-03/0124.html
* Platforms Affected: Jarvis Entertainment Group, Inc., IkonBoard version 2.1.7b and earlier versions Any operating system Any version |
| Recommendation |
Upgrade to the latest version of IkonBoard (2.1.8 or later), available from the IkonBoard Web site at http://www.ikonboard.com/ |
| Related URL |
CVE-2001-0360 (CVE) |
| Related URL |
2471 (SecurityFocus) |
| Related URL |
6216 (ISS) |
|