vendor:
RoseOnlineCMS
by:
cr4wl3r
7.5
CVSS
HIGH
Local File Inclusion
CWE
Product Name: RoseOnlineCMS
Affected Version From: 3 B1
Affected Version To: 3 B1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2009
RoseOnlineCMS <= 3 B1 (admin) Local File Inclusion
The RoseOnlineCMS version 3 B1 is vulnerable to Local File Inclusion (LFI) attack. This exploit works only if the magic_quotes_gpc setting is turned off. An attacker can exploit this vulnerability to include and execute arbitrary local files on the server.
Mitigation:
To mitigate this vulnerability, it is recommended to enable magic_quotes_gpc setting in the server configuration or update to a patched version of RoseOnlineCMS.