LB5000 Cookie Input Validation Vulnerability

LB5000 is a Web Bulletin Board Service (BBS) software package written in Perl which runs on several web server platforms.

It may be possible for a remote attacker, under some circumstances, to put
files on a host running LB5000. This may be used, at the very least,
to gain BBS administrator privileges on LB5000. However, in some
circumstances an attacker may be able to upload an arbitrary script and
execute it to potentially gain local access on the host.


 

Privacy Statement
Copyright 2010, SecurityFocus