filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_path parameter.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/8448.php | vdb entry patch vendor advisory |
http://www.securityfocus.com/bid/4284 | exploit vdb entry patch vendor advisory |
http://www.phprojekt.com/modules.php?op=modload&name=News&file=article&sid=19&mode=&order= | |
http://www.securityfocus.com/archive/1/261676 | mailing list vendor advisory |