Description
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery SQL Injection (1.5.30)
WordPress Plugin BackWPup Multiple Unspecified Vulnerabilities (3.2.1)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4718)
WordPress Plugin Theme Editor Arbitrary File Download (2.5)
WordPress Plugin Themify Portfolio Post Cross-Site Scripting (1.1.5)