Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _AMGconfig[cfg_serverpath] parameter in (1) modules/AllMyGuests/signin.php (aka the Nuke module) and (2) AllMyGuests/signin.php (aka the standalone).
References
Configurations
Information
Published : 2006-09-25 19:07
Updated : 2017-10-18 18:29
NVD link : CVE-2006-4993
Mitre link : CVE-2006-4993
JSON object : View
CWE
Products Affected
voice_of_web
- allmyguests