|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
ViSiON-X contains a flaw that may allow a regular user to gain elevated privileges or execute arbitrary programs. The issue is due to the upload Matrix not properly sanitizing file names and storing files in the main BBS directory. An attacker could upload a file named VISION-X.EXE, COMMAND.COM, or COMMAND.EXE which would be executed the next time the BBS was run.
|
|
Classification |
Location:
Dialup Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
|
|
Solution |
Upgrade to version 2.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Bulletin Board
 |
0.98 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|