What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1.
Explanation of Vulnerability in Simple Terms
02Summary
Compute Links version 1.2.1 and earlier contains a vulnerability that allows an attacker to execute arbitrary code on the site. The vulnerability requires user interaction—a victim must visit a malicious link or page. Once exploited, the attacker gains full control over the site, including the ability to read, modify, or delete data, and disrupt service.
What an attacker can do
03Attacker Capabilities
Run arbitrary code on the site and take full control of it.
Potential impact on your site
04Site Impact
Complete compromise of the site, including data theft, defacement, and service disruption.
Conditions required to exploit
05Prerequisites
A victim must click a malicious link or visit an attacker-controlled page.
Key dates
06Disclosure timeline
August 19, 2024
CVE published
April 28, 2026
Record updated