Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dayfox_blog | Dayfox_designs | 4 (including) | 4 (including) |