PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lan_management_system | Lan_management_system | 1.5.3 (including) | 1.5.3 (including) |
Lan_management_system | Lan_management_system | 1.5.4 (including) | 1.5.4 (including) |