Описание
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-49544
- https://github.com/geraldoalcantara/CVE-2023-49544
- https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion
- https://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html
Связанные уязвимости
CVSS3: 4.9
nvd
почти 2 года назад
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.