vendor:
Hailboards
by:
xoron
7.5
CVSS
HIGH
Remote File Inclusion
94
CWE
Product Name: Hailboards
Affected Version From: 1.2.2000
Affected Version To: 1.2.2000
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Hailboards v1.2.0 (phpbb_root_path) Remote File Include Exploit
This exploit takes advantage of a vulnerability in Hailboards v1.2.0 where it allows remote file inclusion. By including a malicious file through the 'phpbb_root_path' parameter, an attacker can execute arbitrary code on the target system. The exploit code is provided in the given link.
Mitigation:
To mitigate this vulnerability, it is recommended to update Hailboards to a patched version that addresses this issue. Additionally, it is advised to sanitize user input and implement proper input validation in the application.