CVE
- Id
- 2956
- CVE No.
- CVE-2001-0135
- Status
- Candidate
- Description
- The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.
- Phase
- Proposed (20010214)
- Votes
- MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall
- Comments
- Christey> XF:ultraboard-cgi-perm | URL:http://xforce.iss.net/static/5931.php | Frech> XF:ultraboard-cgi-perm(5931) | In description, "writeable": from | http://www.dictionary.com/cgi-bin/dict.pl?term=Writable: Writable | Writ"a*ble, a. Capable of, or suitable for, being written down. | Christey> Yeah yeah yeah, Andre, I knew you"d catch my bad spelling :-)