vendor:
Ptifo mod-CH_212_installed
by:
xoron
7.5
CVSS
HIGH
Remote File Include
CWE
Product Name: Ptifo mod-CH_212_installed
Affected Version From: v2.1.2
Affected Version To: v2.1.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Categories hierarchy v2.1.2 (phpbb_root_path) Remote File Include Exploit
This is a remote file include exploit for Categories hierarchy v2.1.2 script. It allows an attacker to include a remote file by manipulating the 'phpbb_root_path' parameter in the 'class_template.php' file.
Mitigation:
To mitigate this vulnerability, the developer should ensure that user-supplied input is properly validated and sanitized before including it in file paths.