PHP remote file inclusion vulnerability in check_noimage.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the config[path_src_include] parameter.
References
Configurations
Information
Published : 2007-11-15 14:46
Updated : 2008-11-14 23:02
NVD link : CVE-2007-5994
Mitre link : CVE-2007-5994
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
yappa-ng
- yappa-ng