vendor:
by:
Cold z3ro
N/A
CVSS
MEDIUM
Remote File Inclusion
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
MAMBO Modules SWmenu 4.0 (ImageManager.php) Remote File Include Vulnerabilities
The vulnerability allows an attacker to include a remote file via the 'mosConfig_absolute_path' parameter in the ImageManager.php file.
Mitigation:
Update to a patched version of the software.