pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pafiledb | Php_arena | 3.1 (including) | 3.1 (including) |