vendor:
patBBCode
by:
milw0rm.com
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: patBBCode
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
PHP-Tools patBBCode Remote File Inclusion Vulnerability
The vulnerability allows remote attackers to include arbitrary files via a URL in the 'example' parameter.
Mitigation:
Upgrade to a patched version of the software or sanitize user input before including files.