This host is running All In One Control Panel (AIOCP) and is prone to remote file inclusion vulnerability.
Successful exploitation will allow attacker to execute arbitrary code in the context of an application. Impact Level: Application
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
The flaw is caused by improper validation of user-supplied input via the 'page' parameter in cp_html2xhtmlbasic.php that allows the attackers to execute arbitrary code on the web server.
All In One Control Panel (AIOCP) 1.4.001 and prior
- 4Images <= 1.7.1 Directory Traversal Vulnerability
- AIOCP 'cp_html2xhtmlbasic.php' Remote File Inclusion Vulnerability
- ArticleSetup Multiple Cross-Site Scripting and SQL Injection Vulnerabilities
- Atutor AContent Multiple SQL Injection and XSS Vulnerabilities
- Advantech Studio 'NTWebServer.exe' Directory Traversal Vulnerability