COMMAND

    CGIForum

SYSTEMS AFFECTED

    CGIForum 1.0

PROBLEM

    'zorgon' found following.  CGIForum is  a free forum.  We can  set
    'thesection' parameter to view files on the vulnerable system with
    privileges of the user "nobody".

    This is caused from OutputHTMLFile function in cgiforum.pl  script
    where $section (= $thesection )   isn't checked (never besides  in
    this script).

    e.g.:

        http://127.0.0.1/cgi-bin/cgiforum.pl?thesection=../../../../../../etc/passwd%00

SOLUTION

    The author is informed.  Markus Triska has released a new  version
    of CGIForum:

        http://www.marcbrinkmann.de/inandonline/netz/CGIForum-1.01.tar.gz