vendor:
GuppY
by:
irk4z
7.5
CVSS
HIGH
Remote File Inclusion
22
CWE
Product Name: GuppY
Affected Version From: 4.6.2003
Affected Version To: 4.6.2003
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
GuppY 4.6.3 (includes.inc selskin) Remote File Inclusion
The vulnerability allows an attacker to include a remote or local file in the application's code, which can result in arbitrary code execution or information disclosure.
Mitigation:
Update to the latest version of the GuppY software to fix the vulnerability. Review and validate user input before using it in file inclusion functions.