vendor:
LAN Management System
by:
Kw3[R]Ln
7.5
CVSS
HIGH
Remote File Inclusion (RFI)
CWE
Product Name: LAN Management System
Affected Version From: 1.9.2000
Affected Version To: 1.9.2006
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
LMS – LAN Management System 1.9.6 – RFI
The vulnerability allows remote attackers to execute arbitrary code by including a remote file in the vulnerable application.
Mitigation:
The vulnerability can be mitigated by implementing proper input validation and sanitization techniques.