PHProjekt "path_pre" and "lib_path" Parameters Remote File Inclusion Vulnerabilities
Description
A vulnerability has been identified in PHProjekt, which could be exploited by attackers to execute arbitrary commands. This flaw is due to input validation errors in the "lib/specialdays.php" and "lib/dbman_filter.inc.php" scripts that fail to validate the "path_pre" and "lib_path" parameters, which could be exploited by remote attackers to include malicious files and execute arbitrary commands with the privileges of the web server.
Vulnerable Products
Vulnerable Software: PHProjekt version 5.1 and prior