PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Movie_review | Built2go | 1a (including) | 1a (including) |
Movie_review | Built2go | 2a (including) | 2a (including) |
Movie_review | Built2go | 2b (including) | 2b (including) |