A vulnerability has been identified in Socketwiz Bookmarks, which could be exploited by attackers to execute arbitrary commands. This flaw is due to an input validation error in the "smarty_config.php" script that does not validate the "root_dir" parameter, which could be exploited by remote attackers to include malicious files and execute arbitrary commands with privileges of the web server.
Vulnerable Products
Vulnerable Software: Socketwiz Bookmarks version 2.0 and prior