CVE-2008-4206 Information

Description

PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier when register_globals is enabled allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.

Reference

http://e-rdc.org/v1/news.php?readmore=108 http://osvdb.org/48269 http://secunia.com/advisories/31794 http://securityreason.com/securityalert/4307 http://www.securityfocus.com/archive/1/496427/100/0/threaded http://www.securityfocus.com/bid/31207 https://www.exploit-db.com/exploits/6468

Share on: