Phorecast PHP script before 0.40 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Phorecast |
Paul_m._jones |
* |
0.40 (including) |
References