vendor:
Talkback
by:
SirGod
7.5
CVSS
HIGH
Local File Inclusion/PHPInfo Disclosure
98
CWE
Product Name: Talkback
Affected Version From: 2.3.2006
Affected Version To: 2.3.2006
Patch Exists: YES
Related CWE: N/A
CPE: a:talkback:talkback:2.3.6
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Talkback 2.3.6 Multiple Local File Inclusion/PHPInfo Disclosure
Talkback 2.3.6 is vulnerable to Local File Inclusion and PHPInfo Disclosure. An attacker can exploit this vulnerability to include local files and disclose sensitive information such as the PHP configuration.
Mitigation:
Upgrade to the latest version of Talkback.