Описание
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
Ссылки
- ExploitThird Party Advisory
- Technical Description
- Product
- ExploitThird Party Advisory
- Technical Description
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:oretnom23:customer_support_system:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00731
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 4.9
github
почти 2 года назад
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
EPSS
Процентиль: 72%
0.00731
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-89