Description
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the Language cookie.
Exploits (1)
References (5)
Scores
EPSS
0.0829
EPSS Percentile
92.3%
Details
Status
published
Products (2)
smartisoft/phplistpro
2.0
smartisoft/phplistpro
< 2.0.1
Published
May 22, 2006
Tracked Since
Feb 18, 2026