PHP remote file inclusion vulnerability in lib/class.Database.php in NewP News Publication System 1.0.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the path parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/30086 | vdb entry |
http://securityreason.com/securityalert/1835 | third party advisory |
http://www.securityfocus.com/archive/1/450823/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/20893 | vdb entry exploit |