Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) settings_sql.php, and (3) sources/misc/new_day.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Aardvark_topsites_php | Avatic | 5 (including) | 5 (including) |