vendor:
Zenphoto 1.4.10
by:
hyp3rlinx
7,5
CVSS
HIGH
Local File Inclusion
N/A
CWE
Product Name: Zenphoto 1.4.10
Affected Version From: Zenphoto 1.4.10
Affected Version To: Zenphoto 1.4.10
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Local
2015
Zenphoto 1.4.10 Local File Inclusion
Zen Photos pluginDoc.php PHP file is vulnerable to local file inclusion that allows attackers to read arbitrary server files outside of the current web directory by injecting "../" directory traversal characters, which can lead to sensitive information disclosure, code execution or DOS on the victims web server.
Mitigation:
Vendor Notification: November 10, 2015 December 1, 2015 : Public Disclosure