vendor:
Text Exchange Pro
by:
Yakir Wizman
7,5
CVSS
HIGH
Local file inclusion
22
CWE
Product Name: Text Exchange Pro
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Text Exchange Pro (index.php page) Local file inclusion
Text Exchange Pro is an unique PHP script for running your own text link exchange system. Local file inclusion vulnerability exists in the index.php page of the application, which allows an attacker to read sensitive files from the server.
Mitigation:
Input validation should be done to prevent local file inclusion attacks.