vendor:
phpProfiles
by:
v1per-haCker
7.5
CVSS
HIGH
Remote File Inclusion (RFI)
98
CWE
Product Name: phpProfiles
Affected Version From: v.2.1 Beta
Affected Version To: v.2.1 Beta
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
phpProfiles (RFI)
phpProfiles is vulnerable to Remote File Inclusion (RFI) vulnerability. An attacker can exploit this vulnerability by sending a malicious URL to the vulnerable parameter 'reqpath' in 'body.inc.php', 'body_blog.inc.php' and 'upload_ht.inc.php' files. This malicious URL can be used to execute arbitrary code on the vulnerable server.
Mitigation:
Apply the patch provided by the vendor or upgrade to the latest version of phpProfiles.