Directory traversal vulnerability in system/system.php in Zwii 2.1.1, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote malicious users to include and execute arbitrary local files via directory traversal sequences in the set[template][value] parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
remi jean zwii 2.1.1 |