vendor:
HostBill
by:
Dr.DaShE
N/A
CVSS
N/A
Remote injection
CWE
Product Name: HostBill
Affected Version From: v2.3
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Apache Linux server
Unknown
HostBill script suffering from Remote injection php code exploit
The HostBill script is suffering from a remote injection vulnerability in the PHP code. An attacker can exploit this vulnerability by injecting malicious PHP code into the subject field of the new ticket form.
Mitigation:
The vendor should release a patch to fix this vulnerability. Users are advised to update to the latest version of HostBill to mitigate the risk.