WebBBS contains a flaw that allows a remote attacker to execute arbitrary commands on a vulnerable system. The issue is due to the webbbs_config.pl script not providing proper sanity checking for input passed to the "followup" variable. Using a specially crafted URI, a remote attacker can execute any command on the remote host with the same privileges as the web server.
Classification
Location:
Remote / Network Access
Solution
Upgrade to version 5.01 or higher, as it has been reported to fix this
vulnerability. An upgrade is required as there are no known workarounds.