Description
This script is vulnerable to PHP code injection.
PHP code injection is a vulnerability that allows an attacker to inject custom code into the server side scripting engine. This vulnerability occurs when an attacker can control
all or part of an input string that is fed into an eval() function call. Eval will execute the argument as code.
Remediation
Your script should properly sanitize user input.
References
Related Vulnerabilities
PHP 4.3.0 file disclosure and possible code execution
Drupal Core 4.7.x Arbitrary Code Execution (4.7.0 - 4.7.5)
WordPress Plugin Groundhogg-Marketing Automation & CRM for WordPress Remote Code Execution (1.3.4)
Apache Solr SSRF CVE-2017-3164
WordPress Plugin Arigato Autoresponder and Newsletter Remote Code Execution (2.5.1.9)