CVE-2006-3517 Information

Description

PHP remote file inclusion vulnerability in stats.php in RW::Download when register_globals is enabled allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

Reference

http://securityreason.com/securityalert/1207 http://www.securityfocus.com/archive/1/439524/100/0/threaded http://www.securityfocus.com/bid/18901

Share on: