PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ttforum | Ttcms | 1 (including) | 1 (including) |
Ttforum | Ttcms | 2 (including) | 2 (including) |
Ttforum | Ttcms | 3 (including) | 3 (including) |
Ttforum | Ttcms | 4 (including) | 4 (including) |