PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the cropimagedir parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cropimage_component | Cropimage_component | 1.0 (including) | 1.0 (including) |