Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4) spellcheckwindowframeset.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sphpell | Sphpell | 1.01 (including) | 1.01 (including) |