dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.
2001-07-02T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dcscripts | dcforum | 1.0 | Yes |
Application | dcscripts | dcforum | 2.0 | Yes |
Application | dcscripts | dcforum | 3.0 | Yes |
Application | dcscripts | dcforum | 4.0 | Yes |
Application | dcscripts | dcforum | 5.0 | Yes |
Application | dcscripts | dcforum | 6.0 | Yes |
Application | dcscripts | dcforum_2000 | 1.0 | Yes |