vendor:
phpcrs
by:
Pepelux
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: phpcrs
Affected Version From: <= 2.06
Affected Version To: <= 2.06
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Firefox
2008
phpcrs <= 2.06 / Local File Inclusion Vulnerability
A vulnerability exists in phpcrs version <= 2.06, which allows an attacker to include a local file via the 'importFunction' parameter in the 'frame.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. The website only works with Firefox and to exploit it, the user-agent must be changed.
Mitigation:
Upgrade to the latest version of phpcrs.