vendor:
GeekLog
by:
GolD_M(Mahmnood_ali)
5.5
CVSS
MEDIUM
Remote File Include
CWE
Product Name: GeekLog
Affected Version From: <= 2.x
Affected Version To: <= 2.x
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
GeekLog <= 2.x (BaseView.php) Remote File Include Vulnerabilities
The GeekLog version 2.x is vulnerable to remote file inclusion. The vulnerability exists in the BaseView.php file. An attacker can exploit this vulnerability by including a malicious file through the 'glConf[path_libraries]' parameter.
Mitigation:
Upgrade to a patched version of GeekLog or apply the necessary security fixes. Also, ensure that user input is properly validated and sanitized before including files.