vendor:
AzDG Dating Gold
by:
Unknown
7.5
CVSS
HIGH
Remote File Include
CWE
Product Name: AzDG Dating Gold
Affected Version From: AzDG Dating Gold 3.0.5
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
AzDG Dating Gold Multiple Remote File Include Vulnerabilities
The AzDG Dating Gold application fails to properly sanitize user-supplied input, which leads to multiple remote file-include vulnerabilities. An attacker can exploit these vulnerabilities by injecting a malicious script code through the 'int_path' parameter in the 'footer.php' script. This allows the attacker to execute arbitrary remote files and potentially compromise the application and the underlying system.
Mitigation:
To mitigate these vulnerabilities, it is recommended to apply the latest security patches and updates provided by the vendor. Additionally, input validation and sanitization should be implemented to prevent remote file-include attacks.