PoC Index

CVE-2003-0770

HIGH 7.5EPSS 11.1%

FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
11.08% chance of exploitation in the next 30 days, 96th percentile
Published
2003-09-12
Updated
2024-08-08

Proof-of-concept exploits (1)

ExploitDB entries (2)

References

Related