Security Advisory

CVE-2006-1839

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-04-19 16:00:00
Last updated 2024-08-07 17:27:29
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.