QID 730954
Date Published: 2023-10-25
QID 730954: Fusion Hypertext Preprocessor (PHP) Local File Inclusion in Forum Infusion Vulnerability
PHP-Fusion is a free and open-source web framework based on PHP
Affected Version
PHPFusion 9.10.30 and earlier versions.
QID detection logic (Un-Auth)
This qid send GET request to "/fusion/index.php" to check software version
Exploitation of this vulnerability can lead to remote code execution (RCE) if an attacker can acquire some means of uploading a crafted payload file with the .php extension to any known absolute path on the target system.
Solution
Please refer to PHP advisory: cve-2023-2453 for patching details
Vendor References
CVEs related to QID 730954
Software Advisories
| Advisory ID | Software | Component | Link |
|---|