CARE2X.Remote.File.Inclusion

description-logoDescription

It indicates a possible exploit of a PHP remote file inclusion vulnerability in CARE2X.
This flaw is due to input validation errors in "include/inc_news_save.php" when processing the "root_path" parameter.

affected-products-logoAffected Products

CARE2X version 2.2.2 and prior.

Impact logoImpact

The execution of arbitrary PHP code on the system.

recomended-action-logoRecommended Actions

Currently we are not aware of any official supplied fix for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-12-11 16.978