PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.
References
Configurations
Information
Published : 2006-04-19 09:06
Updated : 2018-10-18 09:36
NVD link : CVE-2006-1839
Mitre link : CVE-2006-1839
JSON object : View
CWE
Products Affected
php_album
- php_album


