PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path parameter.
| Software | From | Fixed in |
|---|---|---|
| phpadsnew / phpadsnew | 2.0.5 | 2.0.5.x |
| gianluca_baldo / phpauction | 2.1 | 2.1.x |