Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.15975
Category:CGI abuses
Title:SIR GNUBoard Remote File Inclusion
Summary:NOSUMMARY
Description:Description:

It is possible to make the remote web server read arbitrary files by
using the GNUBoard CGI suite which is installed.

An attacker may use this flaw to inject arbitrary code in the remote
host and gain a shell with the privileges of the web server.

Solution : Upgrade to the latest version
Risk factor : High

Cross-Ref: BugTraq ID: 11948
Common Vulnerability Exposure (CVE) ID: CVE-2004-1403
http://www.securityfocus.com/bid/11948
Bugtraq: 20041215 STG Security Advisory: [SSA-20041214-14] GNUBoard PHP injection vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=110313585810712&w=2
http://sir.co.kr/?doc=bbs/gnuboard.php&bo_table=pds&page=1&wr_id=1871
http://secunia.com/advisories/13479/
XForce ISS Database: gnuboard-doc-index-file-include(18494)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18494
CopyrightThis script is Copyright (C) 2004 Tenable Network Security

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.