#VU54931 PHP file inclusion in R-SeeNet - CVE-2021-21804
Published: July 16, 2021
R-SeeNet
Advantech Co., Ltd
Description
The vulnerability allows a remote attacker to include and execute arbitrary PHP files on the server.
The vulnerability exists due to incorrect input validation when including PHP files in the "sub_opt" parameter in the options.php script functionality. A remote attacker can send a specially crafted HTTP request to the affected application, include and execute arbitrary PHP code on the system with privileges of the web server.