vendor:
Free File Hosting
by:
Kacper (a.k.a Rahim)
7,5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: Free File Hosting
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: YES
Related CWE: N/A
CPE: free-php-scripts.net/P/Free_File_Hosting
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Free File Hosting <= 1.1 (forgot_pass.php) Remote File Include Exploit
A vulnerability in Free File Hosting version 1.1 allows an attacker to include a remote file on the vulnerable server. This can be exploited to execute arbitrary PHP code by including a malicious file from a remote location.
Mitigation:
Upgrade to the latest version of Free File Hosting.