Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) aide or (2) perso parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Eva-web |
Eva-web |
* |
2.2 (including) |
References