[] NeoSense

UltraBoard 1.6 - Denial of Service

Author: Juan M. Bello Rivas
type: dos
platform: cgi
port: 
date_added: 2000-05-05 
date_updated: 2012-07-17 
verified: 1 
codes: CVE-2000-0426;OSVDB-1314 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/1175/info

UltraBoard 1.6 (and possibly all 1.x versions and the new beta Ultraboard 2000) are vulnerable to this Denial of Service attack.

A remote user is able to expend all of the available resources of the webserver by using a specially-devised request to the CGI. This request causes a fork, which will then consume the processor time and memory of the server.

http:://target/ultraboard.pl?request=Session=../UltraBoard.pl%00%7c