PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web_community | Cliserv | 0.50 (including) | 0.50 (including) |
Web_community | Cliserv | 0.60 (including) | 0.60 (including) |
Web_community | Cliserv | 0.61 (including) | 0.61 (including) |
Web_community | Cliserv | 0.65 (including) | 0.65 (including) |