vendor:
LinPHA
by:
EgiX
9.3
CVSS
HIGH
Remote Command Execution
94
CWE
Product Name: LinPHA
Affected Version From: 1.3.2003
Affected Version To: 1.3.2003
Patch Exists: YES
Related CWE: N/A
CPE: a:linpha:linpha
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
LinPHA <= 1.3.3 (maps plugin) Remote Command Execution Exploit
LinPHA <= 1.3.3 is vulnerable to a remote command execution vulnerability due to an LFI found by rgod in /plugins/maps/map.main.class.php. An attacker can modify the 'maps_type' config value by another script and include an arbitrary local file through the require_once() at line 24. The attacker can then include a ChangeLog file containing malicious code to execute arbitrary commands.
Mitigation:
Upgrade to the latest version of LinPHA.