vendor:
ThinkEdit
by:
r0ut3r
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: ThinkEdit
Affected Version From: 1.9.2002
Affected Version To: 1.9.2002
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2006
ThinkEdit Remote File Inclusion Exploit
This exploit allows an attacker to include remote files in the ThinkEdit software. The vulnerability was discovered by r0ut3r and can be exploited by sending a specially crafted request. The vulnerability was found in ThinkEdit version 1.9.2.
Mitigation:
The vendor should release a patch to fix the vulnerability. In the meantime, users of ThinkEdit should be cautious and avoid including remote files in their configurations.