CVE-2001-0360

ikonboard < 2.1.7b - Directory Traversal via help.cgi helpon Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0360. PoCs published by Martin J. Muench.

AI-analyzed exploit summary This writeup describes a directory traversal vulnerability in Ikonboard, where a null byte can be used to bypass the '.dat' suffix restriction, allowing arbitrary file disclosure via path traversal sequences.

Description

Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Martin J. Muench · textremotecgi
https://www.exploit-db.com/exploits/20683

This writeup describes a directory traversal vulnerability in Ikonboard, where a null byte can be used to bypass the '.dat' suffix restriction, allowing arbitrary file disclosure via path traversal sequences.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Ikonboard (versions not specified)
No auth needed
Prerequisites: Access to the Ikonboard help.cgi script
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6216
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2471
Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-03/0124.html

Scores

EPSS 0.0833
EPSS Percentile 94.4%

Details

Status published
Products (1)
ikonboard.com/ikonboard < 2.1.7b
Published Jun 27, 2001
Tracked Since Feb 18, 2026