Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) body, (2) footer, (3) header, (4) menu_left, or (5) menu_right parameter.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2010/09/17/11 | mailing list |
http://secunia.com/advisories/41001 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2010/09/17/4 | mailing list |
http://www.ocert.org/advisories/ocert-2010-003.html |