Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Advanced_poll | Advanced_poll | 2.0.0 (including) | 2.0.0 (including) |
Advanced_poll | Advanced_poll | 2.0.1 (including) | 2.0.1 (including) |
Advanced_poll | Advanced_poll | 2.0.2 (including) | 2.0.2 (including) |