vendor:
Stud.IP
by:
Hamid Ebadi
7,5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Stud.IP
Affected Version From: studip 1.3.0-2
Affected Version To: studip 1.3.0-2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Stud.IP Remote File Inclusion
Stud.IP is a learning and an information management system for universities, educational facilities and enterprises. Stud.IP is vulnerable to Remote File Inclusion vulnerability which allows an attacker to execute arbitrary PHP code by including files from local or external resources.
Mitigation:
Edit the source code to ensure that input is properly verified.