vendor:
Newscoop
by:
High-Tech Bridge SA Security Research Lab
7,5
CVSS
HIGH
Remote File Inclusion
94
CWE
Product Name: Newscoop
Affected Version From: 3.5.3
Affected Version To: 4.0 RC3
Patch Exists: YES
Related CWE: CVE-2012-1933
CPE: a:sourcefabric:newscoop
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
Multiple Remote File Inclusion in Newscoop
Input passed via the "GLOBALS[g_campsiteDir]" GET parameter to /include/phorum_load.php, /conf/install_conf.php and /conf/liveuser_configuration.php is not properly verified before being used in require_once() function and can be exploited to include arbitrary remote files.
Mitigation:
Fixed by Vendor