vendor:
Tour de France Pool for Joomla
by:
Unknown
7.5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: Tour de France Pool for Joomla
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: NO
Related CWE:
CPE: a:tour_de_france_pool:tour_de_france_pool:1.0.1
Platforms Tested: Unknown
Unknown
Tour de France Pool for Joomla Remote File Include Vulnerability
The Tour de France Pool for Joomla is vulnerable to a remote file-include vulnerability. The application fails to properly sanitize user-supplied input, allowing an attacker to include and execute arbitrary files remotely. Exploiting this vulnerability can lead to compromise of the application and the underlying system. Other attacks may also be possible.
Mitigation:
It is recommended to update to the latest version of Tour de France Pool for Joomla to mitigate this vulnerability. Additionally, input validation and sanitization should be implemented to prevent remote file inclusion vulnerabilities.