vendor:
AForum
by:
ThE TiGeR
N/A
CVSS
N/A
Remote file inclusion
CWE
Product Name: AForum
Affected Version From: 1.33
Affected Version To: 1.33
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
2007
AForum 1.33 Remote file inclusion (Func.php)
The AForum version 1.33 is vulnerable to remote file inclusion in the Func.php file. An attacker can exploit this vulnerability by injecting a malicious shell.txt file through the CommonAbsDir parameter in the URL. This allows the attacker to execute arbitrary code on the affected server.
Mitigation:
Unknown