Security Advisory
CVE-2006-4363
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the cropimagedir parameter.