Vulnerabilities > CVE-2000-1176 - Unspecified vulnerability in Yabb 20000911
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | YaBB 9.11.2000 search.pl Arbitrary Command Execution Vulnerability. CVE-2000-1176. Remote exploit for cgi platform |
id | EDB-ID:20387 |
last seen | 2016-02-02 |
modified | 2000-11-07 |
published | 2000-11-07 |
reporter | rpc |
source | https://www.exploit-db.com/download/20387/ |
title | YaBB 9.11.2000 - search.pl Arbitrary Command Execution Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | YABBSE_CMD_EXEC.NASL |
description | The remote host is using the YaBB SE forum management system. According to its version number, this forum is vulnerable to a code injection bug that could allow an attacker with a valid account to execute arbitrary commands on this host by sending a malformed |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11588 |
published | 2003-05-07 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11588 |
title | YaBB SE < 1.5.2 Multiple Vulnerabilities |
code |
|