7.5
CVSSv2

CVE-2000-1176

Published: 09/01/2001 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in YaBB search.pl CGI script allows remote malicious users to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.

Vulnerable Product Search on Vulmon Subscribe to Product

yabb yabb 2000-09-11

Exploits

source: wwwsecurityfocuscom/bid/1921/info YaBB (Yet Another Bulletin Board) is a popular perl-based bulletin board scripting package search pl, one of several perl scripts which comprise YaBB, fails to properly validate user input which arguments a call to open() A malicious user could supply a string containing '//'-type sequence ...