vendor:
CommunityPortals
by:
Nima Salehi
7,5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: CommunityPortals
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
CommunityPortals <= 1.0 Remote File Include Vulnerability
A remote file include vulnerability exists in CommunityPortals version 1.0 and earlier. An attacker can exploit this vulnerability to execute arbitrary code on the vulnerable system. The vulnerability is due to insufficient sanitization of user-supplied input passed to the 'page' parameter in the 'index.php' script. An attacker can exploit this vulnerability by passing a malicious URL to the vulnerable script.
Mitigation:
Upgrade to the latest version of CommunityPortals.