PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Free_image_hosting | Free_php_scripts | * | 1.0 (including) |