vendor:
by:
Cold z3ro
7.5
CVSS
HIGH
RFI (Remote File Inclusion)
98
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Mambo module Calendar (Agenda) <= 155 (com_calendar.php) Multiple RFI Vuln
The vulnerability allows an attacker to include a remote file from a vulnerable website, which can lead to arbitrary code execution.
Mitigation:
The vulnerability can be mitigated by validating and sanitizing user input before including files.