vendor:
NotFTP
by:
Kacper
5.5
CVSS
MEDIUM
Local File Include
22
CWE
Product Name: NotFTP
Affected Version From: 1.3.2001
Affected Version To: 1.3.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2009
NotFTP 1.3.1 Local File Include
The NotFTP 1.3.1 application is vulnerable to local file inclusion. By manipulating the 'newlang' parameter in the 'config.php' file, an attacker can include arbitrary files, potentially leading to unauthorized access to sensitive information.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of NotFTP or implement proper input validation and sanitization to prevent file inclusion attacks.