PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dotproject | Dotproject | 2.0 (including) | 2.0 (including) |
Dotproject | Dotproject | 2.0.1 (including) | 2.0.1 (including) |
Dotproject | Dotproject | 2.0.2 (including) | 2.0.2 (including) |
Dotproject | Dotproject | 2.0.4 (including) | 2.0.4 (including) |