vendor:
webEdition CMS
by:
eidelweiss
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: webEdition CMS
Affected Version From: 6.1.0.2
Affected Version To: 6.1.0.2
Patch Exists: NO
Related CWE:
CPE: a:webedition:webedition:6.1.0.2
Platforms Tested:
2011
webEdition CMS (DOCUMENT_ROOT) Local File Inclusion vulnerability
This vulnerability allows an attacker to include local files on the server by manipulating the 'index.php' file. By providing a crafted input, an attacker can traverse the file system and access sensitive files.
Mitigation:
Upgrade to a patched version of webEdition CMS.