SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://github.com/Filiplain/LFI-to-RCE-SE-Suite-2.0 | third party advisory exploit |
https://www.exploit-db.com/exploits/51404 | third party advisory vdb entry exploit |