Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _PHPLIB[libdir] parameter to (1) rechnung.php or (2) prepend.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Digitalwebshop | Cardway | 1.110 (including) | 1.110 (including) |
Digitalwebshop | Cardway | 1.120 (including) | 1.120 (including) |
Digitalwebshop | Cardway | 1.128 (including) | 1.128 (including) |