vendor:
Ad Manager Pro
by:
Basti
7,5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: Ad Manager Pro
Affected Version From: 2.6
Affected Version To: 2.6
Patch Exists: YES
Related CWE: N/A
CPE: a:phpwebscripts:ad_manager_pro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Ad Manager Pro 2.6 Remote File Include Vulnerability
Ad Manager Pro 2.6 is vulnerable to a Remote File Include vulnerability. This vulnerability is due to the 'ad.php' and 'common.php' files not properly sanitizing user input supplied to the 'ipath' parameter. An attacker can exploit this vulnerability by supplying a malicious URL to the 'ipath' parameter. This can allow the attacker to execute arbitrary code on the vulnerable system.
Mitigation:
Input validation should be used to ensure that user supplied input is properly sanitized.