CVE-2009-3323 Information

Description

Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP code via a URL in the baros_path parameter to (1) include/common_functions.php and the main_path parameter to (2) lib_users.php (3) lib_stats.php and (4) lib_slots.php in include/lib/.

Reference

http://www.exploit-db.com/exploits/9724 https://exchange.xforce.ibmcloud.com/vulnerabilities/53378

Share on: