Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wap_portal_server | Wap | 1.x (including) | 1.x (including) |