Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Garennes | Gforge | * | 0.6.1 (including) |