PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.
| Software | From | Fixed in |
|---|---|---|
| atthat.com / thatware | 0.5.3 | 0.5.3.x |
| atthat.com / thatware | 0.5.2 | 0.5.2.x |