vendor:
iPhotoAlbum
by:
GloD_M = [Mahmood_ali]
7.5
CVSS
HIGH
Remote File Include
CWE
Product Name: iPhotoAlbum
Affected Version From: v1.1
Affected Version To: v1.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
iPhotoAlbum v1.1 Remote File Include Vulnerability
The iPhotoAlbum v1.1 script is vulnerable to remote file inclusion. An attacker can exploit this vulnerability by including a malicious file through the 'set_menu' parameter in the 'header.php' file. This can lead to arbitrary code execution.
Mitigation:
Upgrade to a newer version of the iPhotoAlbum script that has fixed this vulnerability. Alternatively, remove the 'set_menu' parameter from the 'header.php' file.