SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Join our Affiliate Program
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Forum/Board/Portal)  >  AnyBoard Vendors:  Netbula LLC
AnyBoard Discloses System Information to Remote Users
SecurityTracker Alert ID:  1007563
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Aug 25 2003
Impact:  Disclosure of system information, Disclosure of user information
Exploit Included:  Yes  
Version(s): 9.9
Description:  CyberTalon reported an information disclosure vulnerability in the AnyBoard forum software. A remote user can view system information.

It is reported that a remote user can access the following URL on a target system to obtain information about the AnyBoard application and the web server:

http://[target]/cgi-bin/anyboard.cgi/?cmd=sinfo&all=1

Impact:  A remote user can determine system information, including the system installation path, the web server, the forum configuration file location, and various configuration options.
Solution:  No solution was available at the time of this entry.
Vendor URL:  netbula.com/anyboard/ (Links to External Site)
Cause:  Access control error
Underlying OS:  Linux (Any), UNIX (Any), Windows (Any)
Reported By:  cyber talon <cyber_talon@hotmail.com>
Message History:   None.


 Source Message Contents

Date:  Sat, 23 Aug 2003 20:58:49 -0300
From:  cyber talon <cyber_talon@hotmail.com>
Subject:  AnyBoard v??? Discloses sensitive information to remote users

 

        AnyBoard v??? Discloses sensitive information to remote users
                        Found by: CyberTalon

1. Problem
2. Exploit
3. Info

1. Anyboard v??? discloses very sensitive information about the host's
server, software, directorys, and more. (Note: Version tested was not
identified, but possibly 5.x)

2. www.siterunninganyboard.com/cgi-bin/anyboard.cgi/?cmd=sinfo&all=1

3. Vendor URL: http://netbula.com/anyboard

-CT

_________________________________________________________________
The new MSN 8: advanced junk mail protection and 2 months FREE*
http://join.msn.com/?page=features/junkmail


 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2002, SecurityGlobal.net LLC