vendor:
CommunityPortals
by:
Nima Salehi
7.5
CVSS
HIGH
Remote File Include Vulnerability
98
CWE
Product Name: CommunityPortals
Affected Version From: 1.0 Build 12-31-18
Affected Version To: 1.0 Build 12-31-18
Patch Exists: NO
Related CWE: N/A
CPE: a:communityportals:communityportals
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2006
CommunityPortals Build 12-31-18 Remote File Include Vulnerability
CommunityPortals is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input data. An attacker can exploit this issue to have malicious PHP code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Mitigation:
Input validation should be used to prevent the exploitation of this vulnerability.