vendor:
Sitedepth CMS
by:
H4 / Team XPK
7.5
CVSS
HIGH
Local File Include (LFI)
CWE
Product Name: Sitedepth CMS
Affected Version From: Sitedepth CMS 3.44
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Sitedepth CMS 3.44 Local File Include LFI Exploit
The Sitedepth CMS version 3.44 has a Local File Include vulnerability in the ShowImage.php file. This vulnerability allows an attacker to include arbitrary files from the server, potentially leading to remote code execution.
Mitigation:
The vendor has not provided a patch for this vulnerability. It is recommended to upgrade to a newer version of the CMS or implement proper input validation to prevent LFI attacks.