AlegroCart 1.2.8 - Local/Remote File Inclusion EDB-ID: 38728 CVE: N/A Author: CURESEC RESEARCH TEAM Type: WEBAPPS Platform: PHP Date: 2015-11-16 Vulnerable App: AlegroCart 1.2.8 Affected Product AlegroCart 1.2.8 Patched In Patch AC128_fix_22102015 Path Link http://forum.alegrocart.com/download/file.php?id=1047 Vendor Website http://alegrocart.com/ Vulnerability Type LFI/RFI Remote Exploitable Yes Reported to Vendor 09/29/2015 Disclosed to Public 11/13/2015 Coordination Coordinated release CVSS Medium 6.5 AV:N/AC:L/Au:S/C:C/I:C/A:C Description When retrieving logs, there are no checks on the given parameter. This allows local or remote files to be included and executed or printed. Admin credentials are required to view logs. Proof of Concept (Remote File) Proof of Concept (Local File) Solution TODO: Please note that a newer version might already be available. Reference http://blog.curesec.com/article/blog/AlegroCart-128-LFIRFI-102.html