vendor:
P-Book
by:
Ahmad Maulana a.k.a Matdhule
9
CVSS
CRITICAL
Remote File Inclusion
CWE
Product Name: P-Book
Affected Version From: 1
Affected Version To: 1.17
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2006
P-Book <= 1.17 (pb_lang) Remote File Inclusion
Input passed to the "pb_lang" parameter in admin.php is not properly verified before being used. This can be exploited to execute arbitrary PHP code by including files from local or external resources.
Mitigation:
Sanitize variable $pb_lang on affected files.