A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.
References
Link | Resource |
---|---|
https://github.com/wagnerdracha/ProofOfConcept/blob/main/i3geo_proof_of_concept.txt | Exploit Third Party Advisory |
https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-07-14T21:24:22
Updated: 2022-07-14T21:24:22
Reserved: 2022-06-05T00:00:00
Link: CVE-2022-32409
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-07-14T22:15:08.597
Modified: 2023-08-08T14:21:49.707
Link: CVE-2022-32409
JSON object: View
Redhat Information
No data.
CWE