vendor:
Articles One
by:
Security-Database.com
7,5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Articles One
Affected Version From: 3.1.1
Affected Version To: 3.1.1
Patch Exists: YES
Related CWE: CVE-2018-7491
CPE: a:articlesone:articles_one:3.1.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2018
Articles One Remote File Inclusion Vulnerability
Articles One is prone to a remote file-inclusion vulnerability because it fails to sufficiently sanitize user-supplied input. An attacker can exploit this vulnerability to include arbitrary files from remote Web servers that may contain malicious code and execute it in the context of the Web server process.
Mitigation:
Upgrade to version 3.1.2 or later.