Description
PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter.
Remediation
References
Related Vulnerabilities
PrestaShop Incorrect Authorization Vulnerability (CVE-2020-5293)
Drupal Core 5.x Session Fixation (5.0 - 5.8)
Jboss EAP XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2018-1000632)
WordPress 'wp-admin/options.php' Remote Code Execution Vulnerability (0.6.2 - 2.3.2)
WordPress Plugin Easy Social Icons Cross-Site Scripting (3.1.2)