MEDIUM
Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.12 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/logout.php or certain PHP scripts under (2) admin/, (3) dimensions/, (4) gl/, (5) inventory/, (6) manufacturing/, (7) purchasing/, (8) reporting/, (9) sales/, or (10) taxes/
Published Oct 1, 2007
6.8
MEDIUMCVSS 2.0
EPSS 1.11%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.