vendor:
e-pay
by:
indoushka
7.5
CVSS
HIGH
RFI
98
CWE
Product Name: e-pay
Affected Version From: 1.55
Affected Version To: 1.55
Patch Exists: YES
Related CWE: N/A
CPE: a:epay:e-pay:1.55
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu)
2009
e-pay 1.55 RFI Vulnerability
The vulnerability exists in e-pay 1.55, which allows a remote attacker to include a remote file via the '_REQUEST[read]' parameter in 'a_affil.php' and 'popup.php' scripts. An attacker can exploit this vulnerability to execute arbitrary code on the vulnerable system.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to apply the patch as soon as possible.