Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dodosmail_header_file or (2) dodosmail_footer_file parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dodosmail | Dodos_scripts | * | 2.1 (including) |
Dodosmail | Dodos_scripts | 2.0 (including) | 2.0 (including) |
Dodosmail | Dodos_scripts | 2.0.1 (including) | 2.0.1 (including) |