|
Crea-book contains a flaw that may allow a remote attacker to gain elevated privileges. The issue is due to the admin/configurer2.php script not properly sanitizing user-supplied input before passing it to the config.inc.php3 script. By passing crafted content to the "Fond de la page" (background color) field, an attacker can execute arbitrary PHP code.
|