vendor:
Foro Domus
by:
xoron
7.5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Foro Domus
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Foro Domus v2.10 (phpbb_root_path) Remote File Include Exploit
This exploit allows an attacker to include a remote file in the 'menu.php' script of Foro Domus v2.10. By manipulating the 'sesion_idioma' parameter, an attacker can execute arbitrary commands on the server.
Mitigation:
The vendor should release a patch that properly validates user input and prevents remote file inclusion vulnerabilities.