Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla) 1.0.0rc2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) bu_dir or (2) bu_config[dir] parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Buratinable_templator | Vladimir_menshakov | * | 1.0.0_rc2 (including) |