vendor:
SerWeb
by:
Kw3[R]Ln
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: SerWeb
Affected Version From: 2000.9.4
Affected Version To: 2000.9.4
Patch Exists: NO
Related CWE:
CPE: a:serweb:serweb:0.9.4
Platforms Tested:
2007
SerWeb 0.9.4- Remote FIle Inclusion
The exploit allows an attacker to include a malicious script file via the 'load_lang.php' parameter in SerWeb 0.9.4. By manipulating this parameter, an attacker can execute arbitrary code on the target system.
Mitigation:
Upgrade to a patched version of SerWeb or apply the necessary security fixes.