vendor:
FestOs
by:
cr4wl3r
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: FestOs
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: GNU/Linux
2009
FestOs <= 2.2.1 Multiple RFI Exploit
The FestOs version 2.2.1 is vulnerable to multiple Remote File Inclusion (RFI) exploits. Attackers can include malicious files from a remote server, leading to arbitrary code execution.
Mitigation:
To mitigate this vulnerability, it is recommended to update the FestOs software to a secure version or apply any available patches. Additionally, ensure that the ABSOLUTE_FILE_PATH parameter is properly sanitized and validated.