vendor:
nabopoll
by:
Cr@zy_King
N/A
CVSS
HIGH
Remote File .nclude
CWE
Product Name: nabopoll
Affected Version From: nabopoll 1.x
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Remote File .nclude
This exploit allows an attacker to include remote files by manipulating the 'path' parameter in the 'survey.inc.php' file of the 'nabopoll' script. By providing a malicious URL as the 'path' parameter, an attacker can execute arbitrary code on the target system.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the 'nabopoll' script or apply the necessary security measures to prevent unauthorized file inclusion.