WORK system e-commerce "g_include" Parameter File Inclusion Vulnerabilities
Description
Multiple vulnerabilities have been identified in WORK system e-commerce, which could be exploited by attackers to execute arbitrary commands. These flaws are due to input validation errors in various scripts (e.g. "index.php" and "module/forum/forum.php") that do not validate the "g_include" parameter, which could be exploited by remote attackers to include malicious scripts and execute arbitrary commands with the privileges of the web server.
Vulnerable Products
Vulnerable Software: WORK system e-commerce version 3.0.1 and prior