vendor:
newsSync
by:
GoLd_M = Mahmood_ali
7.5
CVSS
HIGH
Remote File Inclusion
CWE
Product Name: newsSync
Affected Version From: 1.5.0rc6
Affected Version To: 1.5.0rc6
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
newsSync 1.5.0rc6 (nuke_include.php) Remote File Inclusion Exploit
This exploit allows an attacker to include a remote file in the nuke_include.php file of newsSync 1.5.0rc6. By manipulating the 'newsSync_enable_phpnuke_mod' and 'newsSync_NUKE_PATH' parameters, the attacker can execute arbitrary code from a remote server.
Mitigation:
Update to a patched version of newsSync or remove the vulnerable nuke_include.php file.