First published: Tue Jan 09 2001(Updated: )
Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yabb | =2000-09-11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1176 is considered a high severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2000-1176, update the YaBB CGI script to a version that sanitizes user input and prevents directory traversal vulnerabilities.
CVE-2000-1176 affects the YaBB software version 2000-09-11.
CVE-2000-1176 is associated with a directory traversal attack that allows attackers to access arbitrary files on the server.
CVE-2000-1176 can be exploited by remote attackers who can manipulate the 'catsearch' form field.