vendor:
Novaboard
by:
High-Tech Bridge SA - Ethical Hacking & Penetration Testing
7.5
CVSS
HIGH
Local File Inclusion
CWE
Product Name: Novaboard
Affected Version From: 1.1.2004
Affected Version To: prior versions
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
Local File Inclusion in Novaboard
The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in nova_lang variable from cookie.