Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Pl-php |
Pl-php |
0.9_beta (including) |
0.9_beta (including) |
References