Total vulnerabilities in the database
The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to reference a PHP file whose name contains a .gif.php extension.
Software | From | Fixed in |
---|---|---|
phpwebsite / phpwebsite | 0.9.1 | 0.9.1.x |
phpwebsite / phpwebsite | 0.9.2 | 0.9.2.x |
phpwebsite / phpwebsite | 0.9.3.1 | 0.9.3.1.x |
phpwebsite / phpwebsite | 0.9.3.4 | 0.9.3.4.x |
phpwebsite / phpwebsite | 0.9.3.3 | 0.9.3.3.x |
phpwebsite / phpwebsite | 0.9.2.1 | 0.9.2.1.x |
phpwebsite / phpwebsite | 0.10.0 | 0.10.0.x |
phpwebsite / phpwebsite | 0.9.3.2 | 0.9.3.2.x |
phpwebsite / phpwebsite | 0.9.3 | 0.9.3.x |
phpwebsite / phpwebsite | 0.9.0 | 0.9.0.x |