Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execute arbitrary PHP code via (1) a local filename or FTP/share URI in the config_file parameter or (2) a URL in the ptconf[src] parameter.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2006/5163 | vdb entry |
https://www.exploit-db.com/exploits/3000 | exploit |
http://secunia.com/advisories/23508 | exploit third party advisory vendor advisory |