dit.cms contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'menus/side_slideopen/index.php' script not properly sanitizing user input supplied to the 'path' parameter. This may allow an attacker to include a file from from the targeted host or an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Third-party Verified,
Uncoordinated Disclosure
OSVDB:
Web Related
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.