vendor:
S-Gästebuch
by:
ajann
5.5
CVSS
MEDIUM
Remote File Include
98
CWE
Product Name: S-Gästebuch
Affected Version From: 1.5.2003
Affected Version To: 1.5.2003
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
S-Gästebuch <= V.1.5.3 (gb_pfad) Remote File Include Exploit
This exploit allows an attacker to include remote files by manipulating the 'gb_pfad' parameter in the 'functions_inc.php' file. The vulnerability exists in S-Gästebuch version 1.5.3.
Mitigation:
The vendor should release a patch that properly sanitizes user input before including files.