Web Server Creator – Web Portal v 0.1 Multi Vulnerability
The vulnerability allows an attacker to traverse directories and execute malicious code on the vulnerable server. An attacker can send a specially crafted HTTP request containing directory traversal strings (e.g. ../../../../../../../../boot.ini) to the vulnerable server in order to traverse directories and read sensitive files. Additionally, an attacker can inject malicious JavaScript code into the vulnerable web application via the 'pg' parameter in the 'index.php' script. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Finally, an attacker can exploit the 'path' parameter in the 'form.php' script to include arbitrary remote files from external sources.