vendor:
i-doIT
by:
AutoSec Tools
9
CVSS
CRITICAL
Local File Inclusion
98
CWE
Product Name: i-doIT
Affected Version From: 0.9.9-4
Affected Version To: 0.9.9-4
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista + XAMPP
2011
i-doIT 0.9.9-4 Local File Inclusion
A local file inclusion vulnerability in i-doIT 0.9.9-4 can be exploited to include arbitrary files. The proof of concept involves sending a crafted URL to the vulnerable application.
Mitigation:
Input validation should be used to prevent the inclusion of arbitrary files.