HIGH
php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter
Published Sep 2, 2005
7.5
HIGHCVSS 2.0
EPSS 2.61%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.