"value":"PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php"
"value":"** IMPUGNADO ** Vulnerabilidad PHP de inclusi\u00f3n remota de archivos en Trevorchan 0.7 y anteriores permite a atacantes remotos ejectar c\u00f3digo de su elecci\u00f3n a trav\u00e9s del par\u00e1metro tc_config[rootdir] en (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, y (5) banned.php. NOTA: este asunto ha sido impugnado por terceras partes creible, que indican que la variable est\u00f1a asignada antes de su uso en config.php."