PHP remote file inclusion vulnerability in html/modules/extranet_profile/main.php in openEngine 1.9 beta1 allows remote malicious users to execute arbitrary PHP code via a URL in the this_module_path parameter. NOTE: this issue is disputed by CVE because PHP encounters a fatal function-call error on a direct request for the file, before reaching the include statement
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
openengine openengine 1.9_beta2 |
||
openengine openengine 1.9_beta1 |
||
openengine openengine 1.9_beta3 |