vendor:
Vanilla Forum
by:
AutoSec Tools
9
CVSS
CRITICAL
Local File Inclusion
98
CWE
Product Name: Vanilla Forum
Affected Version From: 2.0.17.9
Affected Version To: 2.0.17.9
Patch Exists: N/A
Related CWE: N/A
CPE: a:vanilla_forums:vanilla_forums:2.0.17.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista + XAMPP
2011
Vanilla Forum 2.0.17.9 Local File Inclusion
A local file inclusion vulnerability in Vanilla Forum 2.0.17.9 can be exploited to include arbitrary files. The proof of concept is a URL that includes a path to the Windows win.ini file.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in file operations.