HIGH
Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php, (3) framepoint.php, (4) genpage.php, (5) lienvalider.php, (6) appreciation.php, (7) partenariat.php, (8) rechercher.php, (9) projet.php, (10) propoexample.php, (11) refererpoint.php, or (12) top50.php
Published Sep 19, 2006
7.5
HIGHCVSS 2.0
EPSS 6.46%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.