vendor:
pollxt
by:
vitux
7,5
CVSS
HIGH
Input Validation
20
CWE
Product Name: pollxt
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Variable $mosConfig_absolute_path not sanitized
The pollxt mambo component is vulnerable to an input validation vulnerability due to the lack of sanitization of the $mosConfig_absolute_path variable. This vulnerability can be exploited by an attacker to inject malicious code into the vulnerable application. The attacker can use a dork to find vulnerable websites and then inject malicious code into the vulnerable application by passing the malicious code in the $mosConfig_absolute_path variable.
Mitigation:
Add the code 'defined('_VALID_MOS') or die('Direct access to this location is not allowed.');' before the vulnerable code.