vendor:
sflog! CMS/Blog system
by:
dun
N/A
CVSS
MEDIUM
Multiple Vulnerabilities
22
CWE
Product Name: sflog! CMS/Blog system
Affected Version From: <= 1.00
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2012
sflog! <= 1.00 Multiple Vulnerabilities
The sflog! CMS/Blog system is vulnerable to multiple vulnerabilities including Local File Inclusion (LFI). An attacker can exploit the LFI vulnerability by providing a crafted URL to access sensitive files on the server.
Mitigation:
Update to the latest version of sflog! CMS/Blog system or implement proper input validation and sanitization to prevent LFI attacks.