vendor:
Opencourrier
by:
cr4wl3r
7,5
CVSS
HIGH
Remote File Include (RFI) and Local File Include (LFI)
98
CWE
Product Name: Opencourrier
Affected Version From: 2.03beta
Affected Version To: 2.03beta
Patch Exists: Yes
Related CWE: CVE-2009-4010
CPE: a:openmairie:opencourrier:2.03beta
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2009
Opencourrier 2.03beta (RFI/LFI) Multiple File Include Vulnerability
The vulnerability is caused due to the use of user-supplied input without proper validation. This can be exploited to include arbitrary local or remote files by passing malicious parameters to the vulnerable script.
Mitigation:
Upgrade to the latest version of Opencourrier.