vendor:
oscss2
by:
Stefan Schurtz
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: oscss2
Affected Version From: 2.1.2000
Affected Version To: 2.1.2000
Patch Exists: YES
Related CWE: N/A
CPE: a:oscss:oscss2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
osCSS2 “_ID” parameter Local file inclusion
osCSS2 2.1.0 "_ID" parameter is prone to a LFI vulnerability. The vulnerable code is present in the .htaccess, content.php and page.php files. The PoC-Exploit involves sending a malicious request to the target server with the _ID parameter set to a malicious file path. This can be used to read sensitive files from the server.
Mitigation:
Fixed in svn branche 2.1.0 and reported in develop version 2.1.1