vendor:
phppaleo
by:
Mark Stanislav
7,5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: phppaleo
Affected Version From: 4.8b156
Affected Version To: 4.8b156
Patch Exists: YES
Related CWE: CVE-2012-1671
CPE: //a:phppaleo:phppaleo:4.8b156
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
phpPaleo Local File Inclusion (CVE-2012-1671)
A vulnerability exists in index.php for language handling that allows for local file inclusion using a null-byte attack on the 'lang' GET parameter.
Mitigation:
Upgrade to 4.8b157 or above.