AWOL PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
| Software | From | Fixed in |
|---|---|---|
| topher1kenobe / awol | 2.1 | 2.1.x |
| topher1kenobe / awol | 1.0 | 1.0.x |
| topher1kenobe / awol | 1.2.1 | 1.2.1.x |
| topher1kenobe / awol | 2.01 | 2.01.x |
| topher1kenobe / awol | 2.0 | 2.0.x |
| topher1kenobe / awol | 1.2 | 1.2.x |
| topher1kenobe / awol | 1.0.1 | 1.0.1.x |