vendor:
SnippetMaster Webpage Editor
by:
RoMaNcYxHaCkEr
7.5
CVSS
HIGH
Remote File Include, Remote XSS
94, 79
CWE
Product Name: SnippetMaster Webpage Editor
Affected Version From: 2.2.2002
Affected Version To: 2.2.2002
Patch Exists: No
Related CWE: N/A
CPE: a:snippetmaster:snippetmaster_webpage_editor
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
SnippetMaster Webpage Editor 2,2,2 Multiple Vulnes ( Remote File Include , Remote XSS )
The vulnerability is a Remote File Include and Remote XSS vulnerability. The Remote File Include vulnerability can be exploited by sending a maliciously crafted HTTP request to the vulnerable server, containing a URL in the _SESSION[SCRIPT_PATH] parameter, which can be used to include a remote file from an arbitrary external source. The Remote XSS vulnerability can be exploited by sending a maliciously crafted HTTP request to the vulnerable server, containing a malicious JavaScript code in the language parameter, which will be executed in the browser of the victim.
Mitigation:
Contact the author for a solution.