vendor:
Site-Assistant
by:
ajann
7.5
CVSS
HIGH
Remote File Include
22
CWE
Product Name: Site-Assistant
Affected Version From: <= v0990
Affected Version To: v0990
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Site-Assistant <= v0990(paths[version])Remote File Include Exploit
This exploit allows an attacker to include remote files in the vulnerable application. The vulnerability exists in the 'menu.php' file of Site-Assistant version v0990. By manipulating the 'paths[version]' parameter, an attacker can include arbitrary files from a remote server, potentially leading to remote code execution.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Site-Assistant that fixes the remote file inclusion vulnerability.