vendor:
Net Side Content Management System
by:
sharingan
N/A
CVSS
HIGH
Remote File Inclusion
22
CWE
Product Name: Net Side Content Management System
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Net Side Content Management System Remote File Inclusion Vulnerability
The Net Side Content Management System is vulnerable to remote file inclusion. This can be exploited by an attacker by manipulating the 'cms' parameter in the URL to include arbitrary files from remote servers. The vulnerability exists in two versions of the script, and the proof of concept demonstrates how an attacker can include a remote text shell. This vulnerability allows an attacker to execute arbitrary code on the target system.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the Net Side Content Management System script. Additionally, input validation and sanitization should be implemented to prevent remote file inclusion attacks.