vendor:
Puntal
by:
idelweiss
7,5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Puntal
Affected Version From: 2.1.0
Affected Version To: 2.1.0
Patch Exists: YES
Related CWE: CVE-2010-4195
CPE: o:puntal:puntal:2.1.0
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2010
Puntal 2.1.0 Remote File Inclusion Vulnerability
Puntal version 2.1.0 is vulnerable to remote file inclusion. The vulnerability is located in the "index.php" file when the "page" parameter is passed through GET method. The vulnerable code is located in the "index.php" file.
Mitigation:
Upgrade to the latest version of Puntal.