PHP remote file inclusion vulnerability in authform.inc.php in PHProjekt 4.2.3 and earlier allows remote attackers to include arbitrary PHP code via a URL in the path_pre parameter.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://www.gentoo.org/security/en/glsa/glsa-200412-27.xml | vendor advisory |
http://secunia.com/advisories/13660 | third party advisory patch vendor advisory |
http://www.osvdb.org/12613 | vdb entry |
http://www.securityfocus.com/bid/12116 | vdb entry |
http://securitytracker.com/id?1012708 | vdb entry |
http://www.phprojekt.com/modules.php?op=modload&name=News&file=article&sid=193 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18683 | vdb entry |