Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) includes/cart.inc.php or (2) extras/ext_cats.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Photokorn_gallery | Gtasoft | * | 1.52 (including) |