An unchecked buffer condition exists in the WebBBS software, where long parameter strings sent with GET commands can allow arbitrary code to execute on the system.
By sending a string that is 549 characters in length (including the EIP address) an overflow will occur overwriting the EIP register, thereby allowing arbitrary code to run on the server
The author has released a new version of the software. Be sure to upgrade to v1.17 as soon as possible. WebBBS Home Page