CVE Database
/

CVE-2007-3295

Back to search

CVE-2007-3295

Published: Jun 20, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl code via a .. (dot dot) in the userlanguage profile setting, which sets the userlanguage key of the member hash, and is propagated to the language variable in (1) HelpCentre.pl and (2) ICQPager.pl, (3) the use_lang variable in Subs.pl, and the actlang variable in (4) Post.pl and (5) InstantMessage.pl; as demonstrated by pointing userlanguage to the English folder, modifying English/HelpCentre.lng file to contain Perl statements, and then invoking the help action in YaBB.pl.

VendorProductVersions

n/a

n/a

affected
n/a

References

24529
vdb-entry
x_refsource_BID
37238
vdb-entry
x_refsource_OSVDB
25734
third-party-advisory
x_refsource_SECUNIA
2818
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now