vendor:
by:
IbnuSina
9
CVSS
CRITICAL
Remote Code Execution
89
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
HItamputih Crew
The vulnerability allows an attacker to execute arbitrary code on the target system by injecting a malicious file through the 'INC' parameter in various PHP scripts.
Mitigation:
1. Sanitize user input to prevent code injection.2. Avoid using user input directly in file inclusion statements.3. Regularly update and patch the software to fix vulnerabilities.