Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alsa7R

#37298of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2011-1849
7.5
2011-10-08
Php · Phpmailer · CVE-2010-4914
**Name of the Vulnerable Software and Affected Versions** PHP Classifieds version 7.3 **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `lang path` parameter in the tools/phpmailer/class.phpmailer.php file. **Recommendations** For PHP Classifieds version 7.3, update the tools/phpmailer/class.phpmailer.php file to prevent remote file inclusion attacks by validating and sanitizing the `lang path` parameter. As a temporary workaround, consider restricting access to the class.phpmailer.php file until a patch is available.