Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> YaBB Information Disclosure


Vulnerability Assessment Details

YaBB Information Disclosure

Vulnerability Assessment Summary
Searches for the existence of YaBB.pl

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server contains a CGI script that suffers from an
information disclosure vulnerability.

Description :

The 'YaBB.pl' CGI script is installed on the remote host. This script
has a well documented security flaw that lets a possible hacker read arbitrary
files with the rights of the http daemon (usually root or nobody).

See also :

http://archives.neohapsis.com/archives/bugtraq/2000-09/0072.html

Solution :

Remove 'YaBB.pl' or upgrade to the latest version.

Network Security Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:NR/C:P/A:N/I:N/B:C)

Networks Security ID: 1668

Vulnerability Assessment Copyright: This script is Copyright (C) 2000 Renaud Deraison

Cables, Connectors


Lenovo ThinkStation P520 Workstation 1X 3.70GHz W-2135 No RAM/ GPU/ HDD/ OS picture

Lenovo ThinkStation P520 Workstation 1X 3.70GHz W-2135 No RAM/ GPU/ HDD/ OS

$154.97



Dell Poweredge R630 2x Xeon E5-2680 v3 2.5ghz 24-Cores  32gb  240GB SSD  495w picture

Dell Poweredge R630 2x Xeon E5-2680 v3 2.5ghz 24-Cores 32gb 240GB SSD 495w

$164.99



HP Z640 Tower Workstation Xeon E5 240GB SSD+1TB HDD 64GB RAM NVIDIA Quadro K2200 picture

HP Z640 Tower Workstation Xeon E5 240GB SSD+1TB HDD 64GB RAM NVIDIA Quadro K2200

$239.99



Intel Xeon E5-2699 v3 18 Core 2.3 GHz 45MB SR1XD LGA 2011-3 B Grade CPU picture

Intel Xeon E5-2699 v3 18 Core 2.3 GHz 45MB SR1XD LGA 2011-3 B Grade CPU

$25.95



Intel Xeon E5-2680 v4 SR2N7 2.40GHz 35MB 14-Core LGA2011-3 CPU Processor picture

Intel Xeon E5-2680 v4 SR2N7 2.40GHz 35MB 14-Core LGA2011-3 CPU Processor

$14.99



INTEL Xeon E5-2697 V4 SR2JV 2.30GHZ 45MB 18-Core LGA2011-3 CPU picture

INTEL Xeon E5-2697 V4 SR2JV 2.30GHZ 45MB 18-Core LGA2011-3 CPU

$30.00



INTEL SRF8Z XEON-GOLD 6244 3.6GHZ 8C 150W picture

INTEL SRF8Z XEON-GOLD 6244 3.6GHZ 8C 150W

$89.00



INTEL XEON E5-2695V4 SR2J1 2.10GHZ CPU PROCESSOR picture

INTEL XEON E5-2695V4 SR2J1 2.10GHZ CPU PROCESSOR

$27.00



Dell Poweredge R730 | 2x Xeon E5-2699 v3 2.3ghz 36-Cores | 64gb | H730 picture

Dell Poweredge R730 | 2x Xeon E5-2699 v3 2.3ghz 36-Cores | 64gb | H730

$234.99



Intel Xeon E5-2680v4 2.4GHz 14 Core 35MB LGA2011-3 CPU (LOT) SR2N7 picture

Intel Xeon E5-2680v4 2.4GHz 14 Core 35MB LGA2011-3 CPU (LOT) SR2N7

$29.99



Discussions

No Discussions have been posted on this vulnerability.