vendor:
Feederator
by:
NoGe
7.5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Feederator
Affected Version From: 1.0.5
Affected Version To: 1.0.5
Patch Exists: NO
Related CWE: N/A
CPE: a:recly:feederator:1.0.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Feederator – RSS manager Component 1.0.5 Multiple Remote File Inclusion Vulnerabilities
Feederator - RSS manager Component 1.0.5 is vulnerable to multiple Remote File Inclusion vulnerabilities. The vulnerable files are add_tmsp.php, edit_tmsp.php, subscription.php and tmsp.php. An attacker can exploit these vulnerabilities by sending a malicious URL to the vulnerable application. The malicious URL contains the malicious code which will be executed on the vulnerable application.
Mitigation:
The application should validate the user input and filter out any malicious code. The application should also restrict the access to the vulnerable files.