vendor:
Gradman
by:
JosS
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: Gradman
Affected Version From: 2000.1.3
Affected Version To: 2000.1.3
Patch Exists: YES
Related CWE: N/A
CPE: a:gradman:gradman
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Gradman <= 0.1.3 (agregar_info.php?tabla=) Local File Inclusion Exploit
Gradman is vulnerable to a local file inclusion vulnerability. This vulnerability is caused due to the improper validation of user-supplied input in the 'tabla' parameter of the 'agregar_info.php' script. An attacker can exploit this vulnerability to include arbitrary local files from the web server and execute arbitrary code on the vulnerable system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to upgrade to the latest version of the software.