Security Advisory

CVE-2010-3307

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-10-05 17:00:00
Last updated 2024-09-16 16:42:25
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) body, (2) footer, (3) header, (4) menu_left, or (5) menu_right parameter.