vendor:
Angora Guestbook
by:
AutoSec Tools
9
CVSS
CRITICAL
Local File Inclusion
98
CWE
Product Name: Angora Guestbook
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista + XAMPP
2011
Angora Guestbook 1.5 Local File Inclusion
A local file inclusion vulnerability in Angora Guestbook 1.5 can be exploited to include arbitrary files. The proof of concept is a URL that includes a path to the Windows win.ini file.
Mitigation:
Input validation should be used to prevent the inclusion of arbitrary files.