vendor:
eDocStore
by:
t0pP8uZz & xprog
5.5
CVSS
MEDIUM
Local File Inclusion
22
CWE
Product Name: eDocStore
Affected Version From: Unknown
Affected Version To: Latest versions
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
eDocStore Latest Versions Local File Inclusion Vulnerability
This vulnerability allows an attacker to include local files on the server by manipulating the 'doc_id' parameter in the URL. By replacing the first hex value before the comma, an attacker can include any file on the server.
Mitigation:
The vendor should sanitize user input and validate file inclusion paths to prevent this vulnerability. Users should update to the latest patched version.