pafiledb.php in Pafiledb 3.1 may allow remote malicious users to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
php arena pafiledb 3.1 |