vendor:
mooSocial
by:
Esac
8,8
CVSS
HIGH
Directory Traversal / LFI
22
CWE
Product Name: mooSocial
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: YES
Related CWE: N/A
CPE: cpe:a:moosocial:moo_social
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
mooSocial 1.3 – Multiple Vulnerabilites
mooSocial is vulnerable to a directory traversal / local file inclusion vulnerability, as a result, it was possible for an attacker to load webserver-readable files from the local filesystem (and to execute PHP stored on the server).
Mitigation:
Sanitize the $page variable before being used to load the page.