PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code.
| Software | From | Fixed in |
|---|---|---|
| sir / gnuboard | 3.37 | 3.37.x |
| sir / gnuboard | 3.31 | 3.31.x |
| sir / gnuboard | 3.32 | 3.32.x |
| sir / gnuboard | 3.39 | 3.39.x |
| sir / gnuboard | 3.38 | 3.38.x |
| sir / gnuboard | 3.34 | 3.34.x |
| sir / gnuboard | 3.35 | 3.35.x |
| sir / gnuboard | 3.33 | 3.33.x |
| sir / gnuboard | 3.30 | 3.30.x |
| sir / gnuboard | 3.36 | 3.36.x |