vendor:
Nodesforum
by:
ItSecTeam
7,5
CVSS
HIGH
Multi Remote File Include
94
CWE
Product Name: Nodesforum
Affected Version From: 1.033
Affected Version To: 1.033
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
nodesforum_1.033
The vulnerability exists due to insufficient sanitization of user-supplied input in the '_nodesforum_path_from_here_to_nodesforum_folder' and '_nodesforum_code_path' parameters of the 'erase_user_data.php' and 'pre_output.php' scripts. This can be exploited to execute arbitrary PHP code by including a remote file via a URL in the '_nodesforum_path_from_here_to_nodesforum_folder' and '_nodesforum_code_path' parameters.
Mitigation:
No known mitigation is available.