Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ezdatabase | Indexcor | 2.0 (including) | 2.0 (including) |
| Ezdatabase | Indexcor | 2.1.2 (including) | 2.1.2 (including) |