Security Advisory

CVE-2006-1746

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2006-04-12 22:00:00
Last updated 2024-08-07 17:27:27
Assigner mitre
State PUBLISHED

Description

Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameters, which overwrite the underlying $GLOBALS variable.