PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04, and probably earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this product was referred to as "Allfaclassfieds" in the original disclosure.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/466648/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33798 | vdb entry |
http://www.attrition.org/pipermail/vim/2007-April/001543.html | mailing list |
http://securityreason.com/securityalert/2618 | third party advisory |