vendor:
E-GADS!
by:
Unknown
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: E-GADS!
Affected Version From: 2.2.2006
Affected Version To: 2.2.2006
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
E-GADS! 2.2.6 Remote File Inclusion Vulnerability
This vulnerability allows an attacker to include remote files in the 'common.php' file. By manipulating the 'locale' parameter, an attacker can execute arbitrary code on the server.
Mitigation:
Patch or upgrade to a secure version of the software. Additionally, sanitize user input before including files.