vendor:
by:
KEZZAP66345
7.5
CVSS
HIGH
Remote File Include Exploit
CWE
Product Name:
Affected Version From: Web Content System v2.7.1
Affected Version To: Web Content System v2.7.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
Web Content System <<< v2.7.1 Remote File Include Exploit
This exploit allows remote attackers to include and execute arbitrary files on a vulnerable web server. The vulnerability exists due to the application not properly sanitizing user-supplied input in the 'path[JavascriptEdit]' parameter. An attacker can exploit this vulnerability to include a remote file containing malicious PHP code and execute it on the target system.
Mitigation:
To mitigate this vulnerability, it is recommended to update the Web Content System to a version that does not have this vulnerability. Additionally, ensure that user-supplied input is properly sanitized before using it in file inclusion operations.