vendor:
Open Conference Systems
by:
k1tk4t
9,3
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Open Conference Systems
Affected Version From: 1.1.3
Affected Version To: 1.1.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Open Conference Systems <= 1.1.3 Remote File Inclusion
Open Conference Systems version 1.1.3 and prior are vulnerable to a remote file inclusion vulnerability. This vulnerability is due to the application failing to properly sanitize user-supplied input to the 'fullpath' parameter of the 'theme.inc.php' and 'footer.inc.php' scripts. An attacker can exploit this vulnerability to execute arbitrary PHP code on the vulnerable system with the privileges of the webserver process.
Mitigation:
Upgrade to Open Conference Systems version 1.1.4 or later.