HIGH
Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the renderer parameter to template.tpl.php in (1) barrel/, (2) barry/, (3) mylook/, (4) oerdec/, (5) penguin/, (6) sidebar/, (7) slashdot/, and (8) text-only/ in templates/
Published Jun 10, 2008
7.5
HIGHCVSS 2.0
EPSS 39.03%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.