vendor:
Pluck
by:
Unknown
N/A
CVSS
N/A
File Inclusion, File Disclosure
Unknown
CWE
Product Name: Pluck
Affected Version From: Pluck 4.7
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Pluck Multiple File-Include and File-Disclosure Vulnerabilities
Pluck is prone to multiple file-include and a file-disclosure vulnerabilities because it fails to properly sanitize user-supplied input. An attacker can exploit the local file-include vulnerabilities using directory-traversal strings to view and execute local files within the context of the webserver process. Information harvested may aid in further attacks. An attacker can exploit local file-disclosure vulnerability to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Mitigation:
Unknown