Total vulnerabilities in the database
PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.
Software | From | Fixed in |
---|---|---|
ultrize / timesheet | 1.2.2 | 1.2.2.x |