| VID |
22000 |
| Severity |
40 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The ZeroBoard software is vulnerable to internal file excuetion. ZeroBoard is a freely available, open source PHP-based bulletin board software, and widely used in Korea. Zeroboard versions 4.1pl9 and earlier are vulnerable to internal file excuetion, caused by _zb_path, dir script variable.
* References: http://www.xpressengine.com/18319857
* Platforms Affected: Zeroboard versions 4.1pl9 and earlier Any operating system Any version |
| Recommendation |
Apply the appropriate patch for this vulnerability, as listed in Zeroboard4 site at http://www.xpressengine.com/18319857 |
| Related URL |
(CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
(ISS) |
|