CVE Vulnerabilities

CVE-2001-0436

Published: Jul 02, 2001 | Modified: Dec 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.

Affected Software

Name Vendor Start Version End Version
Dcforum Dcscripts 1.0 (including) 1.0 (including)
Dcforum Dcscripts 2.0 (including) 2.0 (including)
Dcforum Dcscripts 3.0 (including) 3.0 (including)
Dcforum Dcscripts 4.0 (including) 4.0 (including)
Dcforum Dcscripts 5.0 (including) 5.0 (including)
Dcforum Dcscripts 6.0 (including) 6.0 (including)
Dcforum_2000 Dcscripts 1.0 (including) 1.0 (including)

References