PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related serialized data and the last part of the concatenated filename, which creates a file in webroot.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpmemcachedadmin | Phpmemcachedadmin_project | * | 1.2.2 (including) |