PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pages[template] parameter.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.org/files/view/109098/vbadvancedcmps-rfilfi.txt - Exploit | |
References | () http://www.securityfocus.com/bid/51672 - Exploit | |
References | () http://www.vbadvanced.com/forum/showthread.php?s=c4fdb72b5c0751a056e814bf32a26ddb&t=44720 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/72736 - |
Information
Published : 2012-10-01 20:55
Updated : 2024-11-21 01:44
NVD link : CVE-2012-5224
Mitre link : CVE-2012-5224
CVE.ORG link : CVE-2012-5224
JSON object : View
Products Affected
vbadvanced
- vbadvanced_cmps
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')