CVE-2010-0678 Information

Description

PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5 and possibly earlier when register_globals is enabled allows remote attackers to execute arbitrary PHP code via a URL in the includes_directory parameter.

Reference

http://osvdb.org/62340 http://packetstormsecurity.org/1002-exploits/katalog-rfisql.txt http://secunia.com/advisories/38581 http://www.exploit-db.com/exploits/11452

Share on: