PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for http and https URLs.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Autolinks | Autolinks | 2.1 (including) | 2.1 (including) |