← Back

CVE-2019-13396

Published: Jul 10, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.

Affected (8)

1 product
Flightpath
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Getflightpath
From 4.0 to 4.8.3
Version 5.0 beta1
Version 5.0 beta2
Version 5.0 dev1
Version 5.0 dev2
Version 5.0 rc1
Version 5.0 rc2
Version 5.0 rc3

References (4)

Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.