CVE-2001-0214
Way-board - Unauthenticated Arbitrary File Read via db Parameter Null Byte Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-0214. PoCs published by cuctema.
AI-analyzed exploit summary This exploit describes a directory traversal vulnerability in Way-Board via a null byte injection in the 'db' parameter. The advisory explains how an attacker can read arbitrary files outside the web root by appending '%00' to a URL.
Description
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.
Exploits (1)
This exploit describes a directory traversal vulnerability in Way-Board via a null byte injection in the 'db' parameter. The advisory explains how an attacker can read arbitrary files outside the web root by appending '%00' to a URL.