PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-02-13 09:30
Updated : 2018-10-10 12:29
NVD link : CVE-2009-0572
Mitre link : CVE-2009-0572
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
flatnux
- flatnux