pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/19176 | vdb entry |
http://marc.info/?l=bugtraq&m=110720365923818&w=2 | mailing list |