Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_Path parameter to (1) boxes/quotes.php or (2) templates/mangobery/footer.sample.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mangobery_cms | Mangobery_cms | 0.5.5 (including) | 0.5.5 (including) |