vendor:
Dolphin
by:
EgiX
7.5
CVSS
HIGH
Remote PHP Code Injection
Unknown
CWE
Product Name: Dolphin
Affected Version From: 7.0.0
Affected Version To: 7.0.7
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Dolphin <= 7.0.7 (member_menu_queries.php) Remote PHP Code Injection Exploit
This exploit takes advantage of a vulnerability in the member_menu_queries.php file of the Dolphin software version 7.0.7 or below. By manipulating the 'bubbles' parameter in the URL, an attacker can inject arbitrary PHP code into the server.
Mitigation:
Upgrade to a patched version of Dolphin software (7.0.8 or later).