CWE-98

High likelihood

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,228 vulnerabilities with CWE-98
CVE-2015-6461 MEDIUM
Schneider Electric Modicon BMXNOC0401 and BMXNOE/BMXNOR/BMXP3420 Firmware - Remote File Inclusion via Crafted URL
CVSS 5.4
CVE-2014-9186 CRITICAL
Honeywell Experion PKS <R400 - File Inclusion
CVSS 9.8
CVE-2012-10025 CRITICAL
WordPress Advanced Custom Fields <= 3.5.1 - Remote File Inclusion Code Execution
Details
Vulnerabilities 1,228
Exploit Likelihood High