6.4
CVSSv2

CVE-2000-1132

Published: 09/01/2001 Updated: 10/10/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

DCForum cgforum.cgi CGI script allows remote malicious users to read arbitrary files, and delete the program itself, via a malformed "forum" variable.

Vulnerable Product Search on Vulmon Subscribe to Product

dcscripts dcforum 3.0

dcscripts dcforum 4.0

dcscripts dcforum 1.0

dcscripts dcforum 2.0

dcscripts dcforum 5.0

dcscripts dcforum 6.0

Exploits

# source: wwwsecurityfocuscom/bid/1951/info # # DCForum is a commercial cgi script from DCScripts which is designed to facilitate web-based threaded discussion forums # #The script improperly validates user-supplied input, which allows the remote viewing of arbitrary files on the host which are readable by user 'nobody' or the webserver ...