CVE-2009-4220
07.12.2009, 17:30
PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pcConfig[smartyPath] parameter.
Vendor | Product | Version |
---|---|---|
raphael_mazoyer | pointcomma | 𝑥 ≤ 3.8b2 |
raphael_mazoyer | pointcomma | 3.1 |
raphael_mazoyer | pointcomma | 3.1.1 |
raphael_mazoyer | pointcomma | 3.5 |
raphael_mazoyer | pointcomma | 3.5:beta_2 |
raphael_mazoyer | pointcomma | 3.6 |
raphael_mazoyer | pointcomma | 3.8:beta |
raphael_mazoyer | pointcomma | 3.51 |
raphael_mazoyer | pointcomma | 3.51:beta |
raphael_mazoyer | pointcomma | 3.53:beta |
𝑥
= Vulnerable software versions
References