Vulnerabilities
Vulnerable Software
Ikonboard.com:  Security Vulnerabilities
SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter.
CVSS Score
7.5
EPSS Score
0.004
Published
2004-12-31
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.
CVSS Score
7.5
EPSS Score
0.109
Published
2003-09-22
Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag.
CVSS Score
7.5
EPSS Score
0.032
Published
2002-06-25
Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.
CVSS Score
7.5
EPSS Score
0.02
Published
2001-12-06
Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter.
CVSS Score
5.0
EPSS Score
0.034
Published
2001-06-27
register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.
CVSS Score
10.0
EPSS Score
0.023
Published
2001-02-12


Contact Us

Shodan ® - All rights reserved