HIGH
Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faqe parameter to (1) attachs.php, (2) backup.php, (3) badwords.php, (4) categories.php, (5) changepw.php, (6) colorchooser.php, (7) colorwheel.php, (8) dbfiles.php, (9) diraccess.php, (10) faq.php, (11) index.php, (12) kb.php, and (13) stats.php
Published Apr 13, 2010
7.5
HIGHCVSS 2.0
EPSS 2.29%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.