PaintBBS Insecure Default Permissions Vulnerability
BID:3948
Info
PaintBBS Insecure Default Permissions Vulnerability
| Bugtraq ID: | 3948 |
| Class: | Configuration Error |
| CVE: |
CVE-2002-0202 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Posted to the Bugtraq mailing list by John Bissell <[email protected]>. |
| Vulnerable: |
PaintBBS PaintBBS 1.2 |
| Not Vulnerable: | |
Discussion
PaintBBS Insecure Default Permissions Vulnerability
PaintBBS is a collection of CGI scripts and a Java applet. It functions as a web based bulletin board system. The applet acts as a drawing program, and allows users to upload pictures to the bbs. PaintBBS is a japanese product.
Some versions of PaintBBS have been reported to suffer from a weak default configuration. Under the default installation, the configuration file and the cgi-bin directory are world readable. Any remote user may request the directory contents, or the contents of the configuration file. Among the information disclosed is the encrypted value of the administration password.
Later versions of PaintBBS may share this configuration.
PaintBBS is a collection of CGI scripts and a Java applet. It functions as a web based bulletin board system. The applet acts as a drawing program, and allows users to upload pictures to the bbs. PaintBBS is a japanese product.
Some versions of PaintBBS have been reported to suffer from a weak default configuration. Under the default installation, the configuration file and the cgi-bin directory are world readable. Any remote user may request the directory contents, or the contents of the configuration file. Among the information disclosed is the encrypted value of the administration password.
Later versions of PaintBBS may share this configuration.
Exploit / POC
PaintBBS Insecure Default Permissions Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.