Description - PHP Code Execution in phpBook

PHP Code Execution found in phpBook script.

Exploit
Available
Solution
Not available - check vendor's website

Vulnerable scripts: index.php

All posted data stores in PHP-file.

Variable $mail isn't properly sanitized and may contain any PHP Code.

Order Source Code Audit

You may order source code analysis of a website made by eVuln team.The work will be done by experts in website security.