HIGH
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement
Published Sep 12, 2003
7.5
HIGHCVSS 2.0
EPSS 11.08%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.