Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitrary PHP code via a URL in the path[skin] parameter to (1) adminfoot.php, (2) adminhead.php, or (3) adminlogin.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Comdev_one_admin_pro | Comdev | 4.1 (including) | 4.1 (including) |