Description
PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter.
Affected products
- blue_dragon / php_blue_dragonplatinum_2.8.0 – platinum_2.8.0