5
CVSSv2

CVE-2000-1171

Published: 09/01/2001 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote malicious users to ready arbitrary files via a .. (dot dot) attack in the "thesection" parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

markus triska cgiforum 1.0

Exploits

source : wwwsecurityfocuscom/bid/1963/info CGIForum is a commercial cgi script from Markus Triska which is designed to facilitate web-based threaded discussion forums The script improperly validates user-supplied input to the "thesection" parameter If an attacker supplies a carefully-formed URL contaning '//' sequences as argument t ...