SIX-webboard 2.01 File Retrieval Vulnerability
BID:3175
Info
SIX-webboard 2.01 File Retrieval Vulnerability
| Bugtraq ID: | 3175 |
| Class: | Design Error |
| CVE: |
CVE-2001-1115 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered by Hannibal Lector <[email protected]> |
| Vulnerable: |
Sixhead SIX-webboard 2.1 |
| Not Vulnerable: | |
Discussion
SIX-webboard 2.01 File Retrieval Vulnerability
SIX-webboard 2.01 does not filter ".." and "/" from user input, allowing users to enter arbitrary values in order to view or retrieve files not normally accessible to them from the remote host.
SIX-webboard 2.01 does not filter ".." and "/" from user input, allowing users to enter arbitrary values in order to view or retrieve files not normally accessible to them from the remote host.
Solution / Fix
SIX-webboard 2.01 File Retrieval Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.