SaveWeb.Portal.File.Inclusion

description-logoDescription

A PHP remote file inclusion vulnerability in SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php.

affected-products-logoAffected Products

circeOS SaveWebPortal 3.4

Impact logoImpact

Arbitrary PHP code execution.

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)