exploit-db-mirror/exploits/cgi/dos/19899.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

7 lines
No EOL
477 B
Text

source: https://www.securityfocus.com/bid/1175/info
UltraBoard 1.6 (and possibly all 1.x versions and the new beta Ultraboard 2000) are vulnerable to this Denial of Service attack.
A remote user is able to expend all of the available resources of the webserver by using a specially-devised request to the CGI. This request causes a fork, which will then consume the processor time and memory of the server.
http:://target/ultraboard.pl?request=Session=../UltraBoard.pl%00%7c