A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file /simple-online-bidding-system/bidding/index.php. The manipulation of the argument page leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
The product allows user input to control or influence paths or file names that are used in filesystem operations.
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Link | Tags |
---|---|
https://vuldb.com/?id.275037 | third party advisory vdb entry permissions required technical description |
https://vuldb.com/?ctiid.275037 | signature permissions required |
https://vuldb.com/?submit.391657 | third party advisory vdb entry |
https://github.com/Wsstiger/cve/blob/main/simple_include.md | exploit |