Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the theme parameter to (1) themesettings.php or (2) index.php, a different vector than CVE-2006-5497. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Segue_cms | Middlebury_college | * | 1.5.9 (including) |
Segue_cms | Middlebury_college | 1.3.5 (including) | 1.3.5 (including) |
Segue_cms | Middlebury_college | 1.5.7 (including) | 1.5.7 (including) |
Segue_cms | Middlebury_college | 1.5.8 (including) | 1.5.8 (including) |