vendor:
actSite
by:
DNX
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: actSite
Affected Version From: v1.56
Affected Version To: v1.56
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2007
actSite v1.56 (news.php) Local File Inclusion
The actSite v1.56 (news.php) is vulnerable to Local File Inclusion. The vulnerability allows an attacker to include local files from the server by manipulating a POST parameter in the news.php file. By using a specially crafted request, an attacker can include arbitrary files and potentially read sensitive information from the server.
Mitigation:
Install security update to v1.57