Vulnerabilities
Vulnerable Software
Smartisoft:  >> Phplistpro  >> 2.0  Security Vulnerabilities
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the Language cookie.
CVSS Score
7.5
EPSS Score
0.068
Published
2006-05-22
Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. NOTE: The config.php vector is already covered by CVE-2006-1749.
CVSS Score
5.1
EPSS Score
0.1
Published
2006-05-12


Contact Us

Shodan ® - All rights reserved