vendor:
WHMCompleteSolution
by:
Lagripe-Dz
7.5
CVSS
HIGH
Local File Disclosure
22
CWE
Product Name: WHMCompleteSolution
Affected Version From: 3.x.x
Affected Version To: 4.0.x
Patch Exists: Yes
Related CWE: N/A
CPE: a:whmcs:whmcomplete_solution
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux+Apache
2011
WHMCompleteSolution (cart.php) Local File Disclosure
If variable "$a" has a true value, it will set "$templatefile" value by default. However, when "$a" value doesn't match the defaults values, the attacker can control "$templatefile" and use it as (File Disclosure). The attacker can use the URL http://domain.tld/[PATH]/cart.php?a=[wrong_value]&templatefile=[LFD]%00 to exploit this vulnerability.
Mitigation:
Update to the latest version of WHMCS