PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.
| Software | From | Fixed in |
|---|---|---|
| jaws / jaws | 0.5.2 | 0.5.2.x |
| jaws / jaws | 0.5.0 | 0.5.0.x |
| jaws / jaws | 0.5.0_beta2 | 0.5.0_beta2.x |
| jaws / jaws | 0.5.1 | 0.5.1.x |
| jaws / jaws | 0.5.0_beta1 | 0.5.0_beta1.x |