vendor:
Form Tools
by:
RoMaNcYxHaCkEr
7.5
CVSS
HIGH
Remote File Include
CWE
Product Name: Form Tools
Affected Version From: 1.5.0b
Affected Version To: 1.5.0b
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Form tools 1.5.0b Remote File Include
The vulnerability exists in the admin_page_open.php and client_page_open.php files in the Form Tools 1.5.0b software. The vulnerability allows an attacker to include remote files by manipulating the 'g_root_dir' parameter. By exploiting this vulnerability, an attacker can execute malicious code hosted on a remote server.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the software or apply a security patch if available. Additionally, it is advised to validate and sanitize user-supplied input to prevent remote file inclusion attacks.