QID 730837
Date Published: 2023-07-17
QID 730837: Gibbon Local File Inclusion (LFI) Vulnerability
Gibbon v25.0.0 and earlier is vulnerable to a Local File Inclusion (LFI) vulnerability. A remote attacker can exploit the vulnerability and include the content of files present in the installation folder.
Affected Versions:
Gibbon v25.0.0 and earlier
Note: Qualys Threat Research Unit (TRU) found versions prior to 25.0.0 vulnerable to the LFI Vulnerability.
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to include common files like gibbon.sql to check for LFI Vulnerability.
Successful exploitation of the vulnerability may allow a remote attacker to view sensitive files leading to information disclosure.
Solution
Vendor has not released patch yet. To download the latest version of Gibbon, please refer to Gibbon Download Page
Vendor References
CVEs related to QID 730837
Software Advisories
| Advisory ID | Software | Component | Link |
|---|