vendor:
Musoo
by:
GoLd_M
N/A
CVSS
N/A
Remote File Include
CWE
Product Name: Musoo
Affected Version From: 0.21
Affected Version To: 0.21
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Musoo 0.21(GLOBALS[ini_array][EXTLIB_PATH]) Remote File Include
The Musoo 0.21 version is vulnerable to remote file inclusion. The vulnerability exists in the 'msDb.php', 'MusooTemplateLite.php', and 'SoundImporter.php' files. An attacker can exploit this vulnerability by manipulating the 'GLOBALS[ini_array][EXTLIB_PATH]' parameter in the URL to include a malicious file. Three exploits are provided in the text, each targeting a different file.
Mitigation:
The vendor should release a patch to fix the remote file inclusion vulnerability in the affected files. Users are advised to update to the latest version of Musoo to mitigate this issue.