PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the cropimagedir parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cropimage_component | Cropimage_component | 1.0 (including) | 1.0 (including) |