Description
Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.
Affected products
- gnu / phpbook1.3.2
- gnu / phpbook1.0 – 1.0
- gnu / phpbook1.1 – 1.1
- gnu / phpbook1.2 – 1.2
- gnu / phpbook1.3 – 1.3