vendor:
SiteBuilderElite1.2
by:
MhZ91
7.5
CVSS
HIGH
Multiple Remote File Inclusion
94
CWE
Product Name: SiteBuilderElite1.2
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: N/A
Related CWE: N/A
CPE: a:sitebuilderelite:sitebuilder_elite:1.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
SiteBuilderElite1.2 Multiple Remote File Inclusion
SiteBuilderElite1.2 present a variable 'CarpPath' not definited in this file files/carprss.php and files/amazon-bestsellers.php which is exploitable by the variable 'CarpPath' for example http://www.example.com/files/carprss.php?CarpPath=[Evil_Code]
Mitigation:
Input validation should be performed to ensure that untrusted input is not used to access local or remote resources.