vendor:
POWL
by:
kw3rln
5.5
CVSS
MEDIUM
Remote File Inclusion
CWE
Product Name: POWL
Affected Version From: 0.94
Affected Version To: 0.94
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
POWL – 0.94 – Remote File Inclusion Exploit
This is a remote file inclusion exploit for POWL version 0.94. The vulnerable file is htmledit.php located in the plugins/widgets/htmledit/ directory. By manipulating the _POWL[installPath] parameter, an attacker can include malicious scripts from a remote server.
Mitigation:
Update to a patched version of POWL or apply appropriate input validation to prevent remote file inclusion vulnerabilities.