vendor:
Public Media Manager
by:
cr4wl3r
7.5
CVSS
HIGH
Remote File Include
22
CWE
Product Name: Public Media Manager
Affected Version From: 1
Affected Version To: 1.3
Patch Exists: NO
Related CWE:
CPE: a:public_media_manager:public_media_manager:1.3
Platforms Tested:
2009
Public Media Manager <= 1.3 (forms_dir) Remote File Include Vulnerability
The Public Media Manager <= 1.3 has a vulnerability in the forms_dir parameter of the comcal/calmenu.php file. An attacker can include a remote file using the forms_dir parameter, which can lead to remote code execution.
Mitigation:
Update to a patched version of Public Media Manager.