Summary
FireStats is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system
other attacks are also
possible.
FireStats 1.6.1 is vulnerable
prior versions may also be affected.
Solution
The vendor has released 'FireStats 1.6.2' to address this issue. See http://firestats.cc/ for more information.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-2143 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities