vendor:
VS-Link-Partner
by:
ajann
7.5
CVSS
HIGH
Remote File Include
CWE
Product Name: VS-Link-Partner
Affected Version From:
Affected Version To: 2.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
VS-Link-Partner <= 2.1 (script_pfad) Remote File Include Exploit
This is a remote file inclusion vulnerability in the VS-Link-Partner version 2.1. The vulnerability allows an attacker to include a remote file by exploiting the 'script_pfad' parameter in the 'functions_inc.php' file. By manipulating the 'gb_pfad' parameter, an attacker can execute arbitrary code on the server.
Mitigation:
The vendor should release a patch to fix the vulnerability. In the meantime, users should update to the latest version of the software and ensure that the 'script_pfad' parameter is properly sanitized to prevent remote file inclusion attacks.