PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gimescripts_shopping_catalog | Chris_mac | * | 0.9.1 (including) |