vendor:
Xoron
by:
Unknown
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: Xoron
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Xoron Exploit
The xoron exploit allows an attacker to include a remote file by manipulating the phpbb_root_path parameter in the archive_topic.php file. This can be used to execute malicious code or gain unauthorized access to the system.
Mitigation:
Update to a patched version of the software or apply a fix provided by the vendor. Remove any unnecessary or unused features or modules.