vendor:
Xero Portal
by:
XORON
5.5
CVSS
MEDIUM
Local File Inclusion
22
CWE
Product Name: Xero Portal
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Xero Portal v1.2 (phpbb_root_path) Local File Include Vulnerability
The Xero Portal v1.2 script is vulnerable to a Local File Include vulnerability. By manipulating the 'phpbb_root_path' parameter in various admin pages, an attacker can include arbitrary files from a remote server.
Mitigation:
The vendor should release a patch to properly sanitize user input and prevent the Local File Inclusion vulnerability. In the meantime, users should ensure that their Xero Portal v1.2 installation is not accessible to untrusted users.