PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for http and https URLs.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Autolinks | Autolinks | 2.1 (including) | 2.1 (including) |