vendor:
Cdsagenda
by:
ToXiC CreW
N/A
CVSS
HIGH
Remote File Inclusion
22
CWE
Product Name: Cdsagenda
Affected Version From: 4.2.2009
Affected Version To: 4.2.2009
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2006
Cdsagenda 4.2.9 Remote File Inclusion
The Cdsagenda 4.2.9 application is vulnerable to remote file inclusion. The vulnerability allows an attacker to include a remote file by manipulating the 'AGE' parameter in the 'SendAlertEmail.php' page. This can be exploited to execute malicious code.
Mitigation:
The recommended mitigation for this vulnerability is to apply the necessary patches provided by the vendor.