PHP-Proxy Local File Inclusion

Strike ID:
E18-5oq61
CVSS:
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
False Positive:
f
Variants:
1
Year:
2018

Description

This strike simulates an exploitation of a local file inclusion vulnerability present in PHP Proxy. The vulnerability results from the lack of input sanitization when handling the 'q' parameter. By exploiting this flaw, an attacker could read arbitrary files from the server's file system.

CVE