High
CVSS 7.5
Overview
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Cla...
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.
This vulnerability is rated 🟠 HIGH.
Recommended actions: