vendor:
MyNews
by:
GolD_M (Mahmnood_ali)
N/A
CVSS
HIGH
Remote File Include
CWE
Product Name: MyNews
Affected Version From: 4.2.2002
Affected Version To: 4.2.2002
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
MyNews 4.2.2 <= Remote File Include Vulnerability
This vulnerability allows an attacker to include a remote file in the MyNews application, potentially leading to remote code execution. The vulnerability is located in the themefunc.php file, specifically in line 2 where a file is required without proper validation.
Mitigation:
To mitigate this vulnerability, it is recommended to validate user input before including any files. Additionally, it is advised to keep the application up to date with the latest patches and security measures.