Family: CGI abuses --> Category: destructive_attack
PunBB language Paramater Local File Include Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Tries to read a local file with PunBB
Detailed Explanation for this Vulnerability Test
The remote web server contains a PHP script that is affected by a
local file include issue.
The version of PunBB installed on the remote host fails to sanitize
input to the 'language' parameter before storing it in the
'register.php' script as a user's preferred language setting. By
registering with a specially-crafted value, a possible hacker can leverage
this issue to view arbitrary files and possibly execute arbitrary code
on the affected host.
See also :
Update to version 1.2.14 or later.
High / CVSS Base Score : 7
Click HERE for more information and discussions on this network vulnerability scan.