haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web server that contains the code in a lang.php file.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/304779 | mailing list exploit patch |
http://www.securitytracker.com/id?1005869 | vdb entry |
http://www.securityfocus.com/bid/6496 | vdb entry exploit |
http://www.iss.net/security_center/static/10960.php | vdb entry |
http://secunia.com/advisories/7797 | third party advisory |