vendor:
Espace Membre
by:
ajann
5.5
CVSS
MEDIUM
Remote File Include
98
CWE
Product Name: Espace Membre
Affected Version From: 02.01
Affected Version To: 02.01
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
FdWeB Espace Membre <= 2.01(path) Remote File Include Vulnerability
The FdWeB Espace Membre <= 2.01(path) script is vulnerable to remote file inclusion. The vulnerability allows an attacker to include a remote file by manipulating the 'path' parameter in the 'admin_menu.php' file.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and validate file inclusion paths before including them in the code.