Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) _basicfunctions.php, or (2) pageactionauthor.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Aigaion | Aigaion | 1.2.1 (including) | 1.2.1 (including) |