PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by modifying the page parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zpanel | Zpanel | 2.0 (including) | 2.0 (including) |
Zpanel | Zpanel | 2.5_beta (including) | 2.5_beta (including) |
Zpanel | Zpanel | 2.5_beta9 (including) | 2.5_beta9 (including) |
Zpanel | Zpanel | 2.5_beta10 (including) | 2.5_beta10 (including) |