Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the art parameter to (1) admin.php, (2) chart.php, (3) modes.php, or (4) stats.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Downstat | Vmist | * | 1.8 (including) |
Downstat | Vmist | 1.2 (including) | 1.2 (including) |
Downstat | Vmist | 1.3 (including) | 1.3 (including) |
Downstat | Vmist | 1.4 (including) | 1.4 (including) |
Downstat | Vmist | 1.5 (including) | 1.5 (including) |
Downstat | Vmist | 1.6 (including) | 1.6 (including) |
Downstat | Vmist | 1.7 (including) | 1.7 (including) |