Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.
| Software | From | Fixed in |
|---|---|---|
| advanced_poll / advanced_poll | 2.0.0 | 2.0.0.x |
| advanced_poll / advanced_poll | 2.0.1 | 2.0.1.x |
| advanced_poll / advanced_poll | 2.0.2 | 2.0.2.x |