vendor:
GRBoard
by:
make0day@gmail.com
7.5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: GRBoard
Affected Version From: 1.8
Affected Version To: 1.8
Patch Exists: Yes
Related CWE: N/A
CPE: a:grboard:grboard:1.8
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: All
2009
GRBoard 1.8 Remote File Inclusion Vulnerability
GRBoard (VERSION 1.8 )is bulletin board system of Korea. It is freely available for all platforms that supports PHP and MySQL. But I find Remote File Inclusion vulnerability. The vulnerability exists in the form_mail.php file, which includes the db_info.php file. An attacker can exploit this vulnerability by sending a specially crafted request containing an arbitrary file path in the theme parameter.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of GRBoard.