Family: CGI abuses --> Category: attack
phpBannerExchange Template Class Local File Include Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Tries to read a file using phpBannerExchange's template class
Detailed Explanation for this Vulnerability Test
The remote web server contains a PHP script that is prone to a local
file include flaw.
The remote host is running phpBannerExchange, a banner exchange script
written in PHP.
The version of phpBannerExchange installed on the remote host uses a
template class that fails to sanitize user-supplied input before using
it in a PHP 'include()' function. An unauthenticated attacker can
exploit this issue to view arbitrary files and possibly to execute
arbitrary PHP code on the affected system subject to the rights of
the web server user id.
See also :
Unknown at this time.
Low / CVSS Base Score : 2.3
Click HERE for more information and discussions on this network vulnerability scan.