vendor:
DDLCMS
by:
eidelweiss
7,5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: DDLCMS
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE: N/A
CPE: a:ddlcms:ddlcms:2.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
DDLCMS v2.1 (skin) Remote File Inclusion Vulnerability
The 'skin' parameter in FILE thanks.php is not Defined which can allow remote attacker to include remote file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing a malicious URL in the 'skin' parameter.
Mitigation:
Input validation should be used to prevent the inclusion of malicious files.