vendor:
witshare
by:
the_Edit0r
7.5
CVSS
HIGH
Local File Include
22
CWE
Product Name: witshare
Affected Version From: 0.9
Affected Version To: 0.9
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
witshare 0.9 Local File Include Vulnerabilitiy
The witshare 0.9 software is vulnerable to Local File Include. An attacker can exploit this vulnerability by providing a malicious file name in the 'menu' parameter of the index.php file. This can lead to arbitrary file inclusion and potentially execute arbitrary code.
Mitigation:
To mitigate this vulnerability, the developer should validate and sanitize user input before using it in file inclusion functions. The use of a white-list approach is recommended to only allow specific files to be included.