Vulnerabilities > CVE-2001-1115 - Unspecified vulnerability in Sixhead Six-Webboard 2.01

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
sixhead
nessus
exploit available

Summary

generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.

Vulnerable Configurations

Part Description Count
Application
Sixhead
1

Exploit-Db

descriptionSIX-webboard 2.01 File Retrieval Vulnerability. CVE-2001-1115. Remote exploit for cgi platform
idEDB-ID:21068
last seen2016-02-02
modified2001-08-31
published2001-08-31
reporterHannibal Lector
sourcehttps://www.exploit-db.com/download/21068/
titleSIX-webboard 2.01 File Retrieval Vulnerability

Nessus

NASL familyCGI abuses
NASL idSIX_WEBBOARD.NASL
descriptionThe version of the
last seen2020-06-01
modified2020-06-02
plugin id10725
published2001-08-13
reporterThis script is Copyright (C) 2001-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10725
titleSIX-webboard generate.cgi 'content' Parameter Traversal Arbitrary File Access