modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malicious code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpwebsite | Phpwebsite | 0.8.2 (including) | 0.8.2 (including) |