vendor:
Modernbill
by:
Solpot a.k.a (k. Hasibuan)
7,5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Modernbill
Affected Version From: 1.6
Affected Version To: 1.6
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
modernbill ver 1.6 (DIR) Remote File Inclusion
Input passed to the 'DIR' is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.
Mitigation:
Input validation should be performed to ensure that untrusted input is not used to access local or external resources.