CVE-2010-1114 Information

Description

Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php.

Reference

http://www.packetstormsecurity.com/1001-exploits/webservercreator-traversalxssrfi.txt http://www.securityfocus.com/bid/37841 https://exchange.xforce.ibmcloud.com/vulnerabilities/55727

Share on: