Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) P_LIB and (2) P_INDEX parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.13
EPSS Ranking 93.7%