vendor:
PhpSherpa
by:
Dr Max Virus
N/A
CVSS
N/A
Bug in include/config.inc.php
CWE
Product Name: PhpSherpa
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
2007
PhpSherpa
The vulnerability exists in the include/config.inc.php file of PhpSherpa. The code includes a file called connect.inc.php using a variable called $racine. An attacker can exploit this vulnerability by manipulating the racine parameter in the URL to execute arbitrary code.
Mitigation:
Unknown