Zorbat Zorbstats PHP script before 0.9 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Zorbstats | Zorbat | 0.8 (including) | 0.8 (including) |