Total vulnerabilities in the database
Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE'] parameters.
Software | From | Fixed in |
---|---|---|
lussumo / vanilla | 1.1.7 | 1.1.7.x |
lussumo / vanilla | 1.1.5-a | 1.1.5-a.x |
lussumo / vanilla | 1.1.2 | 1.1.2.x |
lussumo / vanilla | 1.0.2 | 1.0.2.x |
lussumo / vanilla | 1.1 | 1.1.x |
lussumo / vanilla | 1.1.5-rc1 | 1.1.5-rc1.x |
lussumo / vanilla | 1.1.4 | 1.1.4.x |
lussumo / vanilla | 1.1.3 | 1.1.3.x |
lussumo / vanilla | 1.1.5 | 1.1.5.x |
lussumo / vanilla | 1.1.6-rc2 | 1.1.6-rc2.x |
lussumo / vanilla | 1.1.9 | 1.1.9.x |
lussumo / vanilla | 1.1.8 | 1.1.8.x |
lussumo / vanilla | 1.0.1 | 1.0.1.x |
lussumo / vanilla | - | 1.1.10.x |
lussumo / vanilla | 1.1.6 | 1.1.6.x |
lussumo / vanilla | 1.0.3 | 1.0.3.x |
lussumo / vanilla | 0.9.2 | 0.9.2.x |
lussumo / vanilla | 1.1.1 | 1.1.1.x |