vendor:
Image_Upload Script
by:
Crackers_Child
7.5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Image_Upload Script
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Image_Upload Script Remote File Inclusion Exploit
This exploit allows an attacker to include a malicious file from a remote server into the target website. By manipulating the 'AD_BODY_TEMP' parameter in various PHP files, the attacker can execute arbitrary code or perform unauthorized actions on the target system.
Mitigation:
To mitigate this vulnerability, the website owner should ensure that user-supplied input is properly validated and sanitized before being used in file inclusion operations. Additionally, the use of a Content Security Policy (CSP) can restrict the types of files that can be included.