vendor:
PHP-Proxy
by:
Ameer Pornillos
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: PHP-Proxy
Affected Version From: 5.1.2000
Affected Version To: 5.1.2000
Patch Exists: NO
Related CWE: CVE-2018-19246
CPE: a:php-proxy:php-proxy:5.1.0
Platforms Tested: XAMPP on Win10_x64
2018
PHP-Proxy 5.1.0 – Local File Inclusion
Downloadable pre-installed version of PHP-Proxy 5.1.0 make use of a default app_key wherein can be used for local file inclusion attacks. This can be used to generate encrypted string which can gain access to arbitrary local files in the server.
Mitigation:
Update PHP-Proxy to a patched version that fixes the local file inclusion vulnerability.