CVE-2019-13396
MEDIUM EXPLOITED NUCLEIFlightPath 4.x-5.0.x - Path Traversal and Local File Inclusion via form_include Parameter
Title source: llmExploitation Summary
CVE-2019-13396 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Mohammed Althibyani. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in FlightPath versions < 4.8.2 and < 5.0-rc2. By manipulating the 'form_include' parameter in a POST request, an attacker can read arbitrary files on the server, such as '/etc/passwd'.
Description
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in FlightPath versions < 4.8.2 and < 5.0-rc2. By manipulating the 'form_include' parameter in a POST request, an attacker can read arbitrary files on the server, such as '/etc/passwd'.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N