vendor:
TopTree
by:
milw0rm.com
7.5
CVSS
HIGH
Remote File Inclusion
22
CWE
Product Name: TopTree
Affected Version From: 2.01a
Affected Version To: 2.01a
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
TopTree <= 2.01a Remote File Inclusion Vulnerability
The vulnerability allows an attacker to include a remote file by manipulating the 'right_file' parameter in the 'tpl_message.php' file. This can lead to remote code execution.
Mitigation:
Upgrade to a patched version of TopTree.