vendor:
Arcadem LE
by:
KnocKout
5.5
CVSS
MEDIUM
Remote File Include
CWE
Product Name: Arcadem LE
Affected Version From: 02.04
Affected Version To: 02.04
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Arcadem LE <= 2.04 Remote File Include Vulnerability
The vulnerability exists in the frontpage_right.php file of Arcadem LE version 2.04. An attacker can exploit this vulnerability by injecting a file through the 'loadadminpage' parameter in the URL.
Mitigation:
The vendor should release a patch or an updated version of the script to fix the vulnerability. In the meantime, users can mitigate the risk by restricting access to the affected file or by implementing proper input validation and sanitization.