Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ezdatabase | Indexcor | 2.0 (including) | 2.0 (including) |
Ezdatabase | Indexcor | 2.1.2 (including) | 2.1.2 (including) |