vendor:
Dating Gold
by:
Unknown
7.5
CVSS
HIGH
Remote File Inclusion
94
CWE
Product Name: Dating Gold
Affected Version From: 3.0.5
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:azdg:dating_gold:3.0.5
Platforms Tested:
Unknown
AzDG Dating Gold multiple remote file-include vulnerabilities
The application fails to properly sanitize user-supplied input, allowing an attacker to execute arbitrary remote files containing malicious script code in the context of the webserver process. This can lead to compromise of the application and the underlying system.
Mitigation:
Update to a patched version of AzDG Dating Gold or apply appropriate security measures to sanitize user input.