vendor:
PNphpBB2
by:
irk4z
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: PNphpBB2
Affected Version From: 1.2i
Affected Version To: 1.2i
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2007
PNphpBB2 <= 1.2i (printview.php phpEx) Local File Inclusion Vuln.
The vulnerability allows an attacker to include local files on the server by manipulating the 'phpEx' parameter in the 'printview.php' script of PNphpBB2 version 1.2i or earlier. This can lead to unauthorized access to sensitive files, such as the '/etc/passwd' file.
Mitigation:
The vendor has released a patch for this vulnerability. It is recommended to update to the latest version of PNphpBB2.