1 results (0.002 seconds)

CVSS: 6.8EPSS: 7%CPEs: 1EXPL: 1

Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execute arbitrary PHP code via a URL in the HTML_MENU_DirPath parameter to (1) config_HTML_MENU.php and (2) config_PHPLM.php in phpwcms_template/inc_script/frontend_render/navigation/. Múltiples vulnerabilidades de inclusión remota de archivo en PHP en phpWCMS XT 0.0.7 BETA y anteriores permiten a atacantes remotos ejecutar código PHP de su elección mediante un URL en el parámetro HTML_MENU_DirPath de (1) config_HTML_MENU.php y (2) config_PHPLM.php en phpwcms_template/inc_script/frontend_render/navigation/. • https://www.exploit-db.com/exploits/4477 http://osvdb.org/38591 http://osvdb.org/38592 http://www.securityfocus.com/bid/25879 http://www.vupen.com/english/advisories/2007/3332 https://exchange.xforce.ibmcloud.com/vulnerabilities/36905 • CWE-94: Improper Control of Generation of Code ('Code Injection') •