Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter in (1) event.php and (2) initialize.php. NOTE: vector 2 was later reported to affect 1.4 as well.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-04-20 03:02
Updated : 2018-10-18 09:37
NVD link : CVE-2006-1890
Mitre link : CVE-2006-1890
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
mywebland
- myevent