PHP remote file inclusion vulnerability in template/barnraiser_01/p_new_password.tpl.php in AROUNDMe 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Aroundme | Aroundme | * | 0.5.2 (including) |
| Aroundme | Aroundme | 0.5.1 (including) | 0.5.1 (including) |