vendor:
PHP Upload Center
by:
GregStar
7,5
CVSS
HIGH
Remote/Local File Inclusion
98
CWE
Product Name: PHP Upload Center
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:php_upload_center:php_upload_center_2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Coding 4 Fun
The vulnerability exists due to insufficient sanitization of user-supplied input passed via the 'language' and 'footerpage' parameters to the 'activate.php' script. This can be exploited to include arbitrary local and remote files by passing directory traversal strings to the 'language' parameter and a URL to the 'footerpage' parameter.
Mitigation:
Input validation should be used to ensure that user-supplied input is properly sanitized.