vendor:
DevMass Shopping Cart
by:
S.W.A.T.
7.5
CVSS
HIGH
Remote File Include
CWE
Product Name: DevMass Shopping Cart
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
DevMass Shopping Cart <= 1.0 Remote File Include Vulnerability
The vulnerability allows an attacker to include a remote file which can lead to remote code execution or other malicious activities. The vulnerable code is located in the file 'admin/kfm/initialise.php' where it includes various files without proper input validation.
Mitigation:
Update to a patched version of the software or implement proper input validation before including files.