CVE-2009-3312 Information

Description

PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier when register_globals is enabled allows remote attackers to execute arbitrary PHP code via a crafted URL in the include_class parameter.

Reference

http://osvdb.org/58181 http://secunia.com/advisories/36730 http://www.exploit-db.com/exploits/9703 http://www.vupen.com/english/advisories/2009/2686 https://exchange.xforce.ibmcloud.com/vulnerabilities/53316

Share on: