PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[sipssys] parameter. NOTE: the products documentation recommends placing the affected file outside of the web root, so the scope of issue is limited to admins who do not, or cannot, follow this recommendation.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Sips | Sips | * | 0.3.1 (including) |
| Sips | Sips | 0.2.2 (including) | 0.2.2 (including) |
| Sips | Sips | 0.2.4 (including) | 0.2.4 (including) |
| Sips | Sips | 0.3.0 (including) | 0.3.0 (including) |
| Sips | Sips | 0.3.0pl1 (including) | 0.3.0pl1 (including) |
| Sips | Sips | 0.3.0pl2 (including) | 0.3.0pl2 (including) |