PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
Link | Tags |
---|---|
https://huntr.dev/bounties/718f1be6-3834-4ef2-8134-907a52009894 | issue tracking patch exploit third party advisory |
https://github.com/tsolucio/corebos/commit/8035e725ecb397348bd50545e90975b699e4f9f2 | third party advisory patch |