Description
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
Remediation
References
Related Vulnerabilities
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4825)
WordPress Plugin MAC PHOTO GALLERY Multiple Security Bypass Vulnerabilities (3.0)
Drupal Improper Input Validation Vulnerability (CVE-2019-6339)
MyBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-24734)
WordPress Plugin Affiliates Multiple Cross-Site Scripting Vulnerabilities (2.13.1)