vendor:
ImgSvr
by:
Unknown
5.5
CVSS
MEDIUM
Local File Inclusion
22
CWE
Product Name: ImgSvr
Affected Version From: Unknown
Affected Version To: 2000.6.20
Patch Exists: YES
Related CWE:
CPE: a:imgsvr_project:imgsvr
Platforms Tested:
2007
ImgSvr Local File Include Vulnerability
ImgSvr is prone to a local file-include vulnerability because it fails to sanitize user-supplied input. Attackers may exploit this issue to access files that may contain sensitive information.
Mitigation:
Update to ImgSvr version 0.6.21 or later.