vendor:
LunarPoll Script
by:
Unknown
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: LunarPoll Script
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
LunarPoll Script Remote File Inclusion Vulnerability
The LunarPoll script is vulnerable to remote file inclusion. An attacker can exploit this vulnerability by injecting a malicious URL in the 'PollDir' parameter of the 'show.php' script, leading to the inclusion of arbitrary remote files.
Mitigation:
The vendor should release a patch to fix the remote file inclusion vulnerability. In the meantime, users are advised to restrict access to the 'show.php' script and sanitize user input to prevent malicious URL injections.