A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.
References
Configurations
History
21 Nov 2024, 07:06
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/wagnerdracha/ProofOfConcept/blob/main/i3geo_proof_of_concept.txt - Exploit, Third Party Advisory | |
References | () https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion - Third Party Advisory |
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-22 |
Information
Published : 2022-07-14 22:15
Updated : 2024-11-21 07:06
NVD link : CVE-2022-32409
Mitre link : CVE-2022-32409
CVE.ORG link : CVE-2022-32409
JSON object : View
Products Affected
softwarepublico
- i3geo
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')