PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the config[openi_dir] parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openi-cms | Openi-cms_group | 1.0.1 (including) | 1.0.1 (including) |
Openi-cms | Openi-cms_group | 1.0.1_beta1 (including) | 1.0.1_beta1 (including) |