vendor:
                    PhotoPost Pro
                by:
                    SecurityFocus
                7.5
                        CVSS
                    HIGH
                    Remote File-Include Vulnerabilities
                    94
                        CWE
                    Product Name: PhotoPost Pro
                    Affected Version From:  4.6
                    Affected Version To:  4.6
                    Patch Exists: NO
                    Related CWE: N/A
                    CPE:  N/A
                    
							Metasploit: 
							N/A
						
                    
							Other Scripts: 
							N/A						
                    Tags: N/A
							CVSS Metrics: N/A
							
									Nuclei References: 
									N/A
								
							Nuclei Metadata: N/A
							Platforms Tested:  N/A
                    2005
                    PhotoPost Pro Multiple Remote File-Include Vulnerabilities
PhotoPost Pro is prone to multiple remote file-include vulnerabilities because the application fails to sufficiently sanitize user-supplied data. Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible. The vulnerable URLs are listed in the text.
Mitigation:
					Input validation should be used to ensure that user-supplied data is properly sanitized.