vendor:
Aplomb Poll
by:
Unknown
7.5
CVSS
HIGH
Remote File Include
CWE
Product Name: Aplomb Poll
Affected Version From: 1.1
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
Aplomb Poll multiple remote file-include vulnerabilities
The Aplomb Poll application fails to properly sanitize user-supplied input, leading to multiple remote file-include vulnerabilities. An attacker can exploit these vulnerabilities to include a remote file containing malicious PHP code and execute it in the context of the webserver process. This can result in a compromise of the application and the underlying system, allowing for various other attacks as well.
Mitigation:
The vendor has not provided a specific mitigation or remediation for this vulnerability.