vendor:
VS-News-System
by:
ajann
7.5
CVSS
HIGH
Remote File Include
CWE
Product Name: VS-News-System
Affected Version From: 1.2.2001
Affected Version To: 1.2.2001
Patch Exists: No
Related CWE: Unknown
CPE:
Platforms Tested: Unknown
Unknown
VS-News-System <= V1.2.1 (newsordner) Remote File Include Exploit
This exploit allows an attacker to include remote files in the VS-News-System version 1.2.1. The vulnerability is present in the 'newsordner' parameter of the 'show_news_inc.php' file. By manipulating the 'newsordner' parameter, an attacker can include a remote file hosted on a different server. This can lead to remote code execution or disclosure of sensitive information.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the VS-News-System. Additionally, input validation and sanitization should be implemented to prevent remote file inclusion attacks.