Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jetbox_cms | Jetbox | 2.1 (including) | 2.1 (including) |
Jetbox_cms | Jetbox | 2.1_sr1 (including) | 2.1_sr1 (including) |