lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php.
References
Configurations
Information
Published : 2010-05-04 09:00
Updated : 2017-09-18 18:30
NVD link : CVE-2009-4834
Mitre link : CVE-2009-4834
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
xpressengine
- zeroboard