vendor:
irsr
by:
Treasure Priyamal
7.5
CVSS
HIGH
Local File Inclusion (LFI)
98
CWE
Product Name: irsr
Affected Version From: 0.2
Affected Version To: 0.2
Patch Exists: NO
Related CWE: N/A
CPE: a:nvisionix:irsr
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
nvisionix Roaming System Remote metasys 0.2 LFI Vulnerability
There is a vulnerability in almost every file directory, for example in the system/default.php file, where a malicious user can exploit the require_once ($globalIncludeFilePath) statement to inject malicious code into the system.
Mitigation:
Disable the register_globals setting in the php.ini configuration file.