Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.
| Software | From | Fixed in |
|---|---|---|
| os4ed / opensis | 4.5 | 4.5.x |
| os4ed / opensis | 4.6 | 4.6.x |
| os4ed / opensis | 4.7 | 4.7.x |
| os4ed / opensis | 4.8 | 4.8.x |
| os4ed / opensis | 4.8.1 | 4.8.1.x |
| os4ed / opensis | 4.9 | 4.9.x |
| os4ed / opensis | 5.0 | 5.0.x |
| os4ed / opensis | 5.1 | 5.1.x |
| os4ed / opensis | 5.2 | 5.2.x |