PHP remote file inclusion vulnerability in tracking.php in Trackeur 1 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: CVE and a third party dispute this vulnerability because header is defined before use. The researcher is known to be unreliable
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/36046 | vdb entry |
http://www.securityfocus.com/archive/1/476671/100/0/threaded | mailing list |
http://www.securityfocus.com/archive/1/476757/100/0/threaded | mailing list |