vendor:
chupix
by:
0in
7.5
CVSS
HIGH
Remote File Inclusion (RFI)
CWE
Product Name: chupix
Affected Version From: 2000.2.3
Affected Version To: 2000.2.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
chupix 0.2.3 /admin/include/header.php RFI
The vulnerability allows an attacker to include a remote file from a malicious server, potentially leading to remote code execution.
Mitigation:
To mitigate this vulnerability, the affected application should sanitize user input and avoid including remote files without proper validation.