vendor:
AdvertisementManager
by:
indoushka
7.5
CVSS
HIGH
Local and remote file-include vulnerabilities
CWE
Product Name: AdvertisementManager
Affected Version From: 3.1.2000
Affected Version To:
Patch Exists: No
Related CWE:
CPE:
Platforms Tested:
AdvertisementManager local and remote file-include vulnerabilities
The AdvertisementManager application fails to sufficiently sanitize user-supplied input, leading to local and remote file-include vulnerabilities. Exploiting these vulnerabilities may allow a remote attacker to obtain sensitive information or compromise the application and the underlying computer.
Mitigation:
Proper input validation and sanitization should be implemented to prevent file-include vulnerabilities. Regularly updating the AdvertisementManager application to the latest version is also recommended.