vendor:
VWar
by:
DNX
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: VWar
Affected Version From: v1.5.0 R15
Affected Version To: v1.5.0 R15
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
VWar <= v1.5.0 R15 (mvcw.php) Remote File Inclusion
The vulnerability exists in the $vwar_root parameter in convert/mvcw.php file, which allows remote attackers to include arbitrary files via a specially crafted request. This can lead to remote code execution.
Mitigation:
No update from vendor till now. A quick fix is to replace the code in convert/mvcw.php line 79 as mentioned in the text.