vendor:
webEdition CMS
by:
Unknown
7.5
CVSS
HIGH
Local File Include
Unknown
CWE
Product Name: webEdition CMS
Affected Version From: webEdition CMS 6.1.0.2
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:webedition:webedition_cms:6.1.0.2
Platforms Tested:
Unknown
webEdition CMS Local File Include Vulnerability
webEdition CMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to view and execute arbitrary local files in the context of the webserver process. This may aid in further attacks.
Mitigation:
Unknown